Online Matrimonial Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-46788

9.8CRITICAL

What is CVE-2023-46788?

The Online Matrimonial Project v1.0 possesses critical security flaws due to multiple Unauthenticated SQL Injection vulnerabilities. An issue arises in the 'uploadphoto()' function within the functions.php file, where the 'id' parameter fails to properly validate incoming character inputs. As a result, these inputs are sent unfiltered to the database, creating an opportunity for malicious actors to execute unauthorized SQL commands that can compromise the integrity and confidentiality of the application’s data.

Affected Version(s)

Online Matrimonial Project 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.