CVE-2023-35071
📛 CVE Title
SQLi in MRV Tech's Logging Administration Panel
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection.This issue affects Logging Administration Panel: before 20230915 .
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2023-35071 on 2026-06-30. Shown when MITRE's text differs from the cvelistV5 mirror.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .
Overview
- State
- PUBLISHED
- Assigner (CNA)
- TR-CERT
- CVSS severity
- CRITICAL
- CVSS score
- 9.8 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 9.8 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-89 - Reserved
- 2023-06-12
- Published
- 2023-09-27 10:05 UTC
- Last updated
- 2024-09-23 22:14 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/35xxx/CVE-2023-35071.json
- Linked Threat
- CVE-2023-35071 — SQLi in MRV Tech's Logging Administration Panel
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2023-09-27 15:18:52 UTC
- NVD last modified
- 2026-06-17 06:04:22 UTC
- NVD CVSS v3.1
- 9.8 / 10 CRITICAL source: iletisim@usom.gov.tr
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.0056 (probability of exploitation in next 30 days)
- EPSS percentile
- 42.14% vs all CVEs — higher = more likely to be exploited, as of 2026-06-30
NVD / KEV / EPSS data refreshed 2026-06-30 18:13 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-39107 - Assigner
- TR-CERT
- Published
- Sep 27, 2023, 8:05:21 AM
- Updated
- May 22, 2026, 7:48:51 AM
- EUVD base score (CVSS 3.1)
-
9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.1700
- Vendors
- MRV Tech
- Products
-
Logging Administration Panel (0 <20230915)
- Aliases
-
GHSA-qgv8-vjqw-q242
ENISA description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| MRV Tech | Logging Administration Panel |
0 (affected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:mrv:logging_administration_panel:*:*:*:*:*:*:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://www.usom.gov.tr/bildirim/tr-23-0560 government-resource
MITRE references (2) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0560 government-resource
- https://www.usom.gov.tr/bildirim/tr-23-0560 government-resource, broken-link
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (3)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.usom.gov.tr/bildirim/tr-23-0560 iletisim@usom.gov.tr Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-23-0560 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0560 iletisim@usom.gov.tr
Indicators (1)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
injection.this
|
no local data | 2026-05-18 21:20 UTC |
Remediations (24)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-16 13:45 UTC -
web:www.cisa.gov
If vulnerabilities cannot be remediated within the recommended timeframes, develop a remediation plan for action and coordination across the organization. The remediation plan should include: Vulnerability remediation constraints Interim mitigation actions to overcome constraints Final actions required to remediate vulnerability
2026-06-16 13:45 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-06-16 13:45 UTC -
web:support.microsoft.com
The May 12, 2026 update for Windows 11, version 25H2 and Microsoft server operating system 24H2 includes security and cumulative reliability improvements in .NET Framework 3.5 and 4.8.1. We recommend that you apply this update as part of your regular maintenance routines. Before you install this update, see the Prerequisites and Restart requirement sections. Summary Security Improvements CVE ...
2026-06-16 13:45 UTC -
web:www.ninjaone.com
The patch is designed to be applied seamlessly through Windows Update mechanisms, with Microsoft providing multiple deployment pathways including direct Windows Update channels and the Microsoft Update Catalog for organizations requiring manual distribution.
2026-06-16 13:45 UTC -
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
2026-05-22 06:42 UTC -
web:cyberpress.org
Three critical vulnerabilities have been disclosed in n8n, the popular open-source workflow automation platform, any one of which could allow an authenticated attacker to achieve remote code execution (RCE) or read arbitrary files from the host server.
2026-05-22 06:42 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-05-22 06:42 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 06:42 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-05-22 06:42 UTC -
web:web.whatsapp.com
Log in to WhatsApp Web for simple, reliable and private messaging on your desktop. Send and receive messages and files with ease, all for free.
2026-05-22 06:42 UTC -
web:www.cisco.com
This document describes a list of software versions that have incorporated fixes for Cisco IOS® XE Software Web UI Cisco bug ID CSCwh87343.
2026-05-22 06:42 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 06:42 UTC -
web:www.secure.com
Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.
2026-05-22 06:42 UTC -
web:patch.com
The best breaking news, stories, and events from the Patch network of local news sites
2026-05-22 04:00 UTC -
web:www.patchcareerinstitute.com
P.A.T.C.H . Career Institute's mission is to provide quality training to students in the medical and vocational field. Our primary focus is to provide affordable, and competitive educational training for low to moderate income students.
2026-05-22 04:00 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-22 04:00 UTC -
web:www.lotro.com
Here are the Release Notes for Update 48.3: A Glorious Hunt, Patch 3 released on Wednesday, May 20, 2026.
2026-05-22 04:00 UTC -
web:github.com
A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.
2026-05-22 04:00 UTC -
web:support.microsoft.com
Improvements This update includes new features and quality improvements that were part of the following update: April 14, 2026—KB5083769 (OS Builds 26200.8246 and 26100.8246) April 30, 2026—KB5083631 (OS Builds 26200.8328 and 26100.8328) Preview This update addresses security vulnerabilities documented in the following guide: May 2026 Security Updates The following summary outlines key ...
2026-05-22 04:00 UTC -
web:forums.ea.com
Broken and Updated Sims 4 Mods and CC: patch 1.124, May 12, 2026 About This Thread This thread tracks Sims 4 mods and CC that have been "broken" or made obsolete by game update 1.124, May 12, 2026, or declared unsupported by their creators.
2026-05-22 04:00 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-22 04:00 UTC -
web:wildrift.leagueoflegends.com
Wild Rift Patch Notes 7.1 Wild Rift Patch 7.1 crashes onto the Rift with fresh runes to remix your playstyle, the unstoppable K'Sante joining the fight, and more.
2026-05-22 04:00 UTC -
web:www.callofduty.com
Make sure you're following @CODUpdates, @Treyarch, @RavenSoftware for critical live communications and track common Live Issues on our Trello Boards. For regular updates about all Call of Duty® related live issues, follow @CODUpdates. For updates about Call of Duty®: Black Ops 7 Multiplayer and Zombies, follow @Treyarch. For regular updates about Call of Duty®: Black Ops 7 Campaign and ...
2026-05-22 04:00 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-35071.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T16:23:57.609Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"government-resource",
"x_transferred"
],
"url": "https://www.usom.gov.tr/bildirim/tr-23-0560"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-35071",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-23T20:14:01.750451Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-23T20:14:10.572Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Logging Administration Panel",
"vendor": "MRV Tech",
"versions": [
{
"lessThan": "20230915 ",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Resul Melih MACIT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection.<p>This issue affects Logging Administration Panel: before 20230915 .</p>"
}
],
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection.This issue affects Logging Administration Panel: before 20230915 .\n\n"
}
],
"impacts": [
{
"capecId": "CAPEC-66",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-66 SQL Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-09-27T08:38:16.779Z",
"orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
"shortName": "TR-CERT"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.usom.gov.tr/bildirim/tr-23-0560"
}
],
"source": {
"advisory": "TR-23-0560",
"defect": [
"TR-23-0560"
],
"discovery": "UNKNOWN"
},
"title": "SQLi in MRV Tech's Logging Administration Panel",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
"assignerShortName": "TR-CERT",
"cveId": "CVE-2023-35071",
"datePublished": "2023-09-27T08:05:21.410Z",
"dateReserved": "2023-06-12T19:32:44.800Z",
"dateUpdated": "2024-09-23T20:14:10.572Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}