CVE-2023-42405: FIT2CLOUD Rackshift

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), bareMetalService.list(), and switchService.list().

Affected products

Published 2023-09-14. Last modified 2026-06-17.