← Back to browse · API

CVE-2023-29154

Severity
HIGH
CVSS
7.2
EPSS
0.41443
Risk score
43.31
CISA KEV
No
PoC
No
Published
2023-06-01
Modified
2025-01-09
First seen
2026-08-07
Aliases
EUVD-2023-32756, GHSA-9HH8-JR7J-VWG8
Products
Contec CO.,LTD.:CONPROSYS HMI System (CHS) versions prior to 3.5.3
Sources
euvd EUVD-2023-32756

Description

SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQL command via specially crafted input to the query setting page.

References