PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-5806 Mergen Software CVE debrief

CVE-2023-5806 is a critical SQL injection vulnerability affecting Mergentech Quality Management System versions before 1.2. NVD assigns a CVSS 3.1 score of 9.8, reflecting a network-reachable issue with no required privileges or user interaction and high impact to confidentiality, integrity, and availability. Organizations running affected versions should treat this as an urgent remediation item and move to a fixed release before 1.2.

Vendor
Mergen Software
Product
Quality Management System
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-01-18
Original CVE updated
2026-05-20
Advisory published
2024-01-18
Advisory updated
2026-05-20

Who should care

Security teams, application owners, and administrators responsible for Mergentech Quality Management System deployments, especially any instance exposed to untrusted networks or handling sensitive records.

Technical summary

The issue is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The NVD record lists the vulnerable CPE as mergentech:quality_management_system with affected versions ending before 1.2. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely exploitable SQL injection condition with severe potential impact.

Defensive priority

Immediate

Recommended defensive actions

  • Confirm whether Quality Management System is deployed in your environment and determine the exact version in use.
  • Upgrade affected installations to version 1.2 or later as soon as possible.
  • If immediate upgrade is not possible, restrict network exposure to trusted administrative paths only.
  • Review application and database logs for unusual queries, errors, or unexpected access patterns around the affected service.
  • Assess whether sensitive data may have been exposed or modified through the vulnerable application.
  • Track remediation status and verify that no older vulnerable instances remain accessible.

Evidence notes

The CVE record was published on 2024-01-18 and later modified on 2026-05-20. NVD lists the affected product as mergentech:quality_management_system with versions before 1.2 and the weakness as CWE-89. The record also links to USOM advisory material, which supports the vulnerability classification and mitigation context. No KEV entry was provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-5806 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-5806

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-5806 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5806

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.