CVE-2023-1547 is a critical SQL Injection vulnerability affecting Elra Parkmatik software versions prior to 02.01-a51. This flaw allows unauthenticated attackers to execute arbitrary SQL commands and potentially gain full control over the affected system by tampering with SOAP parameters. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's no evidence of active exploitation or significant community discussion, the potential for severe compromise necessitates immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 02.01-a51CPE matchmatch criteria | cpe:2.3:a:elra:parkmatik:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.