CVE-2023-39021

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.30 % (70th)
0.30% Progress
Affected Products 1
Advisories 1

wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.

Weaknesses
CWE-94
Improper Control of Generation of Code ('Code Injection')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2023-07-28 15:15:13
(13 months ago)
Updated Date
2023-08-03 18:00:28
(13 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Wix Embedded Mysql 4.6.1 and prior versions cpe:2.3:a:wix:wix_embedded_mysql <= 4.6.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...