CVE detail
CVE-2024-1523 — CVE-2024-1523
Published 2024-02-15 · Modified 2026-06-17 · Vendor e-web · Product fs-ezviewer · Source nvd
HIGH
severity
CVSS-derived band
0.0080
EPSS probability
exploitation probability, 30d
53.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and deleting database records, as well as executing system commands. Attackers may even leverage the dbo privilege in the database for privilege escalation, elevating their privileges to administrator.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References