PatchSiren cyber security CVE debrief
CVE-2023-4541 Ween Software CVE debrief
CVE-2023-4541 is a critical SQL injection affecting Ween Admin Panel / Management Panel through 20231229. NVD classifies the weakness as CWE-89 and assigns a CVSS 3.1 score of 9.8 with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which means the issue is network-reachable, requires no privileges or user interaction, and can have full impact on confidentiality, integrity, and availability. The source advisory also notes that the vendor was contacted early and did not respond.
- Vendor
- Ween Software
- Product
- Admin Panel
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-12-29
- Original CVE updated
- 2026-05-21
- Advisory published
- 2023-12-29
- Advisory updated
- 2026-05-21
Who should care
Security teams and administrators responsible for Ween Admin Panel / Management Panel deployments, especially if the interface is reachable from untrusted networks or used to manage sensitive data.
Technical summary
The supplied NVD record describes CVE-2023-4541 as an SQL injection vulnerability (CWE-89) in Ween Management Panel / Admin Panel affecting versions through 20231229. The recorded CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a remotely exploitable issue with no authentication or user interaction required and high potential impact. A USOM advisory is referenced in the source corpus as third-party validation of the issue.
Defensive priority
Immediate
Recommended defensive actions
- Inventory all Ween Admin Panel / Management Panel instances and identify any systems running a version through 20231229.
- Restrict network access to the administrative interface until the affected systems are patched or otherwise mitigated.
- Apply a vendor-provided fix if one becomes available; if not, remove external exposure or isolate the system.
- Review relevant application and database logs for unusual query patterns, SQL errors, or unexpected administrative activity.
- Treat data handled by exposed instances as potentially at risk until the environment has been validated.
Evidence notes
This debrief is grounded in the CVE record published on 2023-12-29 and the NVD record supplied in the corpus. The record attributes the issue to CWE-89 and provides the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The source description states that the vendor was contacted early but did not respond. The later NVD modified timestamp is record metadata and should not be read as the vulnerability disclosure date.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-4541 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-4541
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-4541 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-4541
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0740
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0740
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.