Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2023-37372

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an unauthenticated remote attackers to execute arbitrary SQL queries on the server database.
Attacker Value
Unknown

CVE-2023-27411

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an authenticated remote attackers to execute arbitrary SQL queries on the server database and escalate privileges.
Attacker Value
Unknown

CVE-2023-27463

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database.
Attacker Value
Unknown

CVE-2023-27462

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to access data they are not authorized for.
Attacker Value
Unknown

CVE-2023-27310

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts.
Attacker Value
Unknown

CVE-2023-27309

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.