SQL Injection Vulnerability in Oretnom23 Judging Management System
CVE-2023-30016

9.8CRITICAL

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
12 January 2024

What is CVE-2023-30016?

A vulnerability exists in Oretnom23's Judging Management System version 1.0, where an SQL Injection flaw in the sub_event_details_edit.php script allows remote attackers to manipulate queries by injecting malicious input through the sub_event_id parameter. This could result in unauthorized execution of arbitrary code, leading to potential exposure of sensitive data and manipulation of the application's database. Proper validation and sanitization of user inputs are essential to mitigate this type of vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.