Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection.This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.
CVE ID: CVE-2023-2907
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.8
Vendor: Marksoft
Product: Marksoft
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 14.91% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)