Online Matrimonial Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-46788
9.8CRITICAL
What is CVE-2023-46788?
The Online Matrimonial Project v1.0 possesses critical security flaws due to multiple Unauthenticated SQL Injection vulnerabilities. An issue arises in the 'uploadphoto()' function within the functions.php file, where the 'id' parameter fails to properly validate incoming character inputs. As a result, these inputs are sent unfiltered to the database, creating an opportunity for malicious actors to execute unauthorized SQL commands that can compromise the integrity and confidentiality of the application’s data.
Affected Version(s)
Online Matrimonial Project 1.0