CVE-2023-3826
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jul 22, 2023
Updated: May 17, 2024
CWE ID 311
Summary
CVE-2023-3826 is a critical vulnerability affecting IBOS OA 4.5.5. An unknown functionality of the Interview Handler component's /?r=recruit/resume/edit&op=status path is exploited through sql injection when the resumeid argument is manipulated. The attack can be launched remotely and the exploit is publicly disclosed, increasing the risk. Vulnerability identifier VDB-235144 relates to this issue. Regrettably, the vendor was unresponsive to early disclosure attempts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- IBM Corporation