PatchSiren cyber security CVE debrief
CVE-2023-35070 VegaGroup CVE debrief
CVE-2023-35070 is a critical SQL injection vulnerability in VegaGroup Web Collection affecting versions before 31197. The NVD record rates it CVSS 3.1 9.8, reflecting a network-exploitable issue with no privileges or user interaction required. Exposed deployments should treat remediation as urgent.
- Vendor
- VegaGroup
- Product
- Web Collection
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-07-13
- Original CVE updated
- 2024-11-21
- Advisory published
- 2023-07-13
- Advisory updated
- 2024-11-21
Who should care
Administrators, security teams, and application owners running VegaGroup Web Collection versions earlier than 31197 should prioritize this issue. Any internet-facing or broadly accessible deployment is especially important to review.
Technical summary
The official record identifies an SQL injection weakness (CWE-89) in VegaGroup Web Collection. NVD lists the vulnerable version range as all versions before 31197, with CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination indicates a remotely reachable flaw that can affect confidentiality, integrity, and availability at high impact if exploited.
Defensive priority
Critical. This issue is rated CVSS 9.8 and should be prioritized ahead of routine maintenance. If VegaGroup Web Collection is in use, confirm whether any instance is below build 31197 and remediate immediately.
Recommended defensive actions
- Upgrade VegaGroup Web Collection to version 31197 or later.
- Inventory all instances of VegaGroup Web Collection and verify their exact build numbers.
- Review exposed deployments first, especially internet-facing systems.
- Monitor application and database logs for abnormal query patterns or unexpected error messages.
- Apply compensating controls such as network restrictions and least-privilege database access until patching is complete.
Evidence notes
The supplied official vulnerability data from NVD lists CVE-2023-35070 as an SQL injection in VegaGroup Web Collection, with affected versions before 31197. NVD also records CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and CWE-89. The reference list includes a USOM third-party advisory. CVE publication date in the supplied timeline is 2023-07-13, with modified date 2024-11-21.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-35070 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-35070
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-35070 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-35070
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0406
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.