PatchSiren cyber security CVE debrief
CVE-2023-35070 VegaGroup CVE debrief
CVE-2023-35070 is a critical SQL injection vulnerability in VegaGroup Web Collection affecting versions before 31197. The NVD record rates it CVSS 3.1 9.8, reflecting a network-exploitable issue with no privileges or user interaction required. Exposed deployments should treat remediation as urgent.
- Vendor
- VegaGroup
- Product
- Web Collection
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-07-13
- Original CVE updated
- 2024-11-21
- Advisory published
- 2023-07-13
- Advisory updated
- 2024-11-21
Who should care
Administrators, security teams, and application owners running VegaGroup Web Collection versions earlier than 31197 should prioritize this issue. Any internet-facing or broadly accessible deployment is especially important to review.
Technical summary
The official record identifies an SQL injection weakness (CWE-89) in VegaGroup Web Collection. NVD lists the vulnerable version range as all versions before 31197, with CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination indicates a remotely reachable flaw that can affect confidentiality, integrity, and availability at high impact if exploited.
Defensive priority
Critical. This issue is rated CVSS 9.8 and should be prioritized ahead of routine maintenance. If VegaGroup Web Collection is in use, confirm whether any instance is below build 31197 and remediate immediately.
Recommended defensive actions
- Upgrade VegaGroup Web Collection to version 31197 or later.
- Inventory all instances of VegaGroup Web Collection and verify their exact build numbers.
- Review exposed deployments first, especially internet-facing systems.
- Monitor application and database logs for abnormal query patterns or unexpected error messages.
- Apply compensating controls such as network restrictions and least-privilege database access until patching is complete.
Evidence notes
The supplied official vulnerability data from NVD lists CVE-2023-35070 as an SQL injection in VegaGroup Web Collection, with affected versions before 31197. NVD also records CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and CWE-89. The reference list includes a USOM third-party advisory. CVE publication date in the supplied timeline is 2023-07-13, with modified date 2024-11-21.
Official resources
-
CVE-2023-35070 CVE record
CVE.org
-
CVE-2023-35070 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
CVE published by NVD/CVE on 2023-07-13 and later modified on 2024-11-21. The supplied corpus does not include a KEV designation.