VYPR
Critical severity9.8NVD Advisory· Published Jun 19, 2023· Updated Jun 17, 2026

CVE-2023-2907

CVE-2023-2907

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection.

This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.

Affected products

5
  • Marksoft/Marksoft2 versions
    cpe:2.3:a:marksoft:marksoft:*:*:*:*:mobile:*:*:*+ 1 more
    • cpe:2.3:a:marksoft:marksoft:*:*:*:*:mobile:*:*:*range: <=7.1.7
    • (no CPE)range: 0
  • Marksoft/APIllm-create
    Range: <=20230605
  • Marksoft/Mobilellm-create
    Range: <=v.7.1.7
  • Marksoft/Loginllm-create
    Range: <=1.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.