Online Voting System Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-48433

9.8CRITICAL

What is CVE-2023-48433?

The Online Voting System Project v1.0 is susceptible to multiple unauthenticated SQL Injection vulnerabilities due to insufficient validation of user input in the 'username' parameter of the login_action.php resource. Malicious actors can exploit this flaw to manipulate database queries, potentially leading to unauthorized data access or manipulation. It's crucial for users of this software to implement robust security measures to mitigate the risks associated with these vulnerabilities.

Affected Version(s)

Online Voting System Project 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-48433 : Online Voting System Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi)