VYPR
High severity7.2NVD Advisory· Published Aug 11, 2023· Updated Jun 17, 2026

CVE-2023-3864

CVE-2023-3864

Description

Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

Affected products

3
  • cpe:2.3:a:snowsoftware:snow_license_manager:*:*:*:*:service_provider:*:*:*+ 1 more
    • cpe:2.3:a:snowsoftware:snow_license_manager:*:*:*:*:service_provider:*:*:*range: >=8.0.0,<=9.30.1
    • (no CPE)range: <=9.30.1
  • Range: 8.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.