IT

Tracker / CVE-2023-3864

CVE-2023-3864

High 7.2

Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

Affected products and versions

snowsoftware snow_license_manager · 8.0.0 → 9.30.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References