Bylancer QuickQR GET Parameter blog sql injection
CVE-2023-3689
9.8CRITICAL
What is CVE-2023-3689?
A SQL injection vulnerability in Bylancer QuickQR version 6.3.7 allows attackers to manipulate the 's' parameter through the GET method. This security flaw can be exploited remotely, potentially leading to unauthorized access to the underlying database. The vendor has not responded to disclosure attempts, emphasizing the need for users to ensure their installations are secure and up-to-date to prevent exploitation.
Affected Version(s)
QuickQR 6.3.7
