CVE-2023-0953: Devolutions Server

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.

Affected products

  • Devolutions Devolutions Server: up to and including 2022.3.12

Published 2023-03-01. Last modified 2026-06-17.