SQL Injection in fossbilling/fossbilling
CVE-2023-3490
9.8CRITICAL
What is CVE-2023-3490?
A SQL Injection vulnerability exists in the FossBilling application, allowing attackers to manipulate database queries through unsanitized input. This flaw, present in versions prior to 0.5.3, poses a significant risk, as it can lead to unauthorized access to sensitive data or influence application behavior. Users are advised to upgrade to the latest version to mitigate potential exploitation.
Affected Version(s)
fossbilling/fossbilling < 0.5.3
