Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-50743

9.8CRITICAL

Key Information:

Vendor
CVE Published:
4 January 2024

What is CVE-2023-50743?

The Online Notice Board System version 1.0, developed by Kashipara, contains multiple vulnerabilities related to unauthenticated SQL injections. The system fails to adequately validate the 'dd' parameter within the registration.php resource, allowing unfiltered user inputs to be sent directly to the database. This flaw poses a significant security risk, as attackers can manipulate SQL queries, potentially compromising the integrity and confidentiality of the database. Immediate remediation is essential to protect against unauthorized data access and exploitation.

Affected Version(s)

Online Notice Board System 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-50743 : Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)