Vulnerability CVE-2023-48118


Published: 2024-01-22

Description:
SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page.

 References:
https://www.quest-analytics.com/
https://github.com/el-dud3rino/CVE-Disclosures/blob/main/Quest%20Analytics%20IQCRM/Proof%20of%20Concept
https://github.com/el-dud3rino/CVE-Disclosures/blob/main/README.md

Copyright 2026, cxsecurity.com

 

Back to Top