Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-50752
9.8CRITICAL
What is CVE-2023-50752?
The Online Notice Board System version 1.0, developed by Kashipara, contains multiple vulnerabilities that allow for Unauthenticated SQL Injection attacks. The application does not properly validate the 'e' parameter in the login.php resource, resulting in unfiltered data being sent to the database. This flaw could enable attackers to manipulate SQL queries, potentially leading to unauthorized data access or compromise of the database integrity.
Affected Version(s)
Online Notice Board System 1.0