CVE-2023-4674

NONENVD 0.09.8
EchelonGraph scoreLOW confidence

Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2023-12-29.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa
0.0

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection.

This issue affects E-Commerce Software: through 20231229. 

NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS v3
EG Score
9.8(low)
EPSS
23.5%
KEV
Not listed

Published

December 29, 2023

Last Modified

May 21, 2026

Frequently asked(4)

What is CVE-2023-4674?
CVE-2023-4674 is a none vulnerability published on December 29, 2023. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: through 20231229. NOTE: The vendor was contacted early about this…
When was CVE-2023-4674 disclosed?
CVE-2023-4674 was first published in the National Vulnerability Database on December 29, 2023, with the most recent update on May 21, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2023-4674 actively exploited?
CVE-2023-4674 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 23.5% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
How do I remediate CVE-2023-4674?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2023-4674, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-4674

Explore →

Is Your Infrastructure Affected by CVE-2023-4674?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.