CVE-2023-34133
80Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.5epss 73%
from disclosure to weapon0 days
Published on NVDJul 13
metasploitJul 12
VulnCheck+126d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesVulnCheck
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N