• caglararli@hotmail.com
  • 05386281520

CVE-2023-43743 | Zultys MX-SE/MX-SE II/MX-E/MX-Virtual/MX250/MX30 prior 16.04 Patch 16109/17.0.10 Patch 17161 Web Interface /newapi/ filter sql injection (ATREDIS-2023-0002)

Çağlar Arlı      -    26 Views

CVE-2023-43743 | Zultys MX-SE/MX-SE II/MX-E/MX-Virtual/MX250/MX30 prior 16.04 Patch 16109/17.0.10 Patch 17161 Web Interface /newapi/ filter sql injection (ATREDIS-2023-0002)

A vulnerability was found in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250 and MX30. It has been classified as critical. Affected is an unknown function of the file /newapi/ of the component Web Interface. The manipulation of the argument filter leads to sql injection. This vulnerability is traded as CVE-2023-43743. The attack needs to be done within the local network. There is no exploit available. It is recommended to upgrade the affected component.