Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-50752
9.8CRITICAL
What is CVE-2023-50752?
The Online Notice Board System version 1.0, developed by Kashipara, contains multiple vulnerabilities that allow for Unauthenticated SQL Injection attacks. The application does not properly validate the 'e' parameter in the login.php resource, resulting in unfiltered data being sent to the database. This flaw could enable attackers to manipulate SQL queries, potentially leading to unauthorized data access or compromise of the database integrity.
Affected Version(s)
Online Notice Board System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved