Online Matrimonial Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-46787

9.8CRITICAL

What is CVE-2023-46787?

The Online Matrimonial Project v1.0 exposes multiple vulnerabilities related to unauthenticated SQL injection. The vulnerability specifically affects the 'username' parameter within the auth/auth.php resource, which fails to properly validate user input. As a result, malicious actors can exploit this flaw to send unfiltered data directly to the database, potentially compromising sensitive information and allowing unauthorized actions.

Affected Version(s)

Online Matrimonial Project 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.