Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-50752

9.8CRITICAL

Key Information:

Vendor
CVE Published:
4 January 2024

What is CVE-2023-50752?

The Online Notice Board System version 1.0, developed by Kashipara, contains multiple vulnerabilities that allow for Unauthenticated SQL Injection attacks. The application does not properly validate the 'e' parameter in the login.php resource, resulting in unfiltered data being sent to the database. This flaw could enable attackers to manipulate SQL queries, potentially leading to unauthorized data access or compromise of the database integrity.

Affected Version(s)

Online Notice Board System 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-50752 : Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)