Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-50743
9.8CRITICAL
What is CVE-2023-50743?
The Online Notice Board System version 1.0, developed by Kashipara, contains multiple vulnerabilities related to unauthenticated SQL injections. The system fails to adequately validate the 'dd' parameter within the registration.php resource, allowing unfiltered user inputs to be sent directly to the database. This flaw poses a significant security risk, as attackers can manipulate SQL queries, potentially compromising the integrity and confidentiality of the database. Immediate remediation is essential to protect against unauthorized data access and exploitation.
Affected Version(s)
Online Notice Board System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved