CVE-2023-4309
Summary
| CVE | CVE-2023-4309 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-10 18:15:00 UTC |
| Updated | 2023-11-07 04:22:00 UTC |
| Description | Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Electionservicesco | Internet Election Service | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| schemasecurity.co/private-elections.pdf | MISC | schemasecurity.co | |
| Election Services Corporation | MISC | www.electionservicesco.com | |
| Please update your browser | MISC | www.youtube.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.