CVE-2023-46806

MEDIUM

Ivanti Endpoint Manager Mobile < 12.1.0.0 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.

References (1)

Core 1

Scores

CVSS v3 6.7
EPSS 0.0097
EPSS Percentile 76.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
ivanti/endpoint_manager_mobile < 12.1.0.0
Published May 22, 2024
Tracked Since Feb 18, 2026