NA

CVE-2023-4537

Published: 15/02/2024 Updated: 15/02/2024

Vulnerability Summary

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects ERP XL: from 2020.2.2 up to and including 2023.2.

Github Repositories

MITM SQL proxy (TLS supported) Tool for MS SQL Man In The Middle attack which supports TLS encryption How it works: It listens for connection pretending to be a real MS SQL Server, decrypts traffic to obtain credentials or manipulate the queries and connect back to real SQL server and forward traffic When possible it downgrades connection to non-encrypted on both sides, if no