CVE-2023-34133
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- May 25, 2023
- Published Date
- July 13, 2023
- Last Updated
- April 23, 2025
- Vendor
- SonicWall
- Product
- GMS, Analytics
- Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- Tags
- Exploitation
- none
- Automatable
- Yes
- Technical Impact
- partial
- Exploited in the Wild
- Yes (2025-07-07 00:00:00 UTC) Source
nuclei_scanner
CVSS Scores
CVSS v3.1
7.5 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC Information
Exploit Status
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| The Shadowserver (via CIRCL) | 2025-07-07 00:00:00 UTC |
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34133.yaml | 2026-06-01 15:34:35 UTC |
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/sonicwall_shell_injection_cve_2023_34124.rb | 2025-04-28 15:02:23 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Metasploit
-
Added to KEVIntel
-
Detected by Nuclei