← Back to browse · API

CVE-2023-4309

Severity
CRITICAL
CVSS
10.0
EPSS
0.01051
Risk score
40.37
CISA KEV
No
PoC
No
Published
2023-10-10
Modified
2024-09-18
First seen
2026-08-07
Aliases
EUVD-2023-54176, GHSA-FFH8-C8RH-CMP2
Products
Election Services Co. (ESC):Internet Election Service 0 ≤2023-08-12
Sources
euvd EUVD-2023-54176

Description

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

References