CVE-2023-35851: Sun.net Wmpro

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.

Affected products

Published 2023-09-18. Last modified 2026-06-17.