CVE-2023-46581

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 14, 2023
Updated: Nov 17, 2023
CWE ID 89

Summary

CVE-2023-46581 is a new SQL injection vulnerability that has been identified in the Inventory Management v.1.0 software. This issue allows local attackers to inject malicious SQL code into the application by manipulating the name, uname, and email parameters in the registration.php component. By exploiting this vulnerability, attackers can gain unauthorized access to sensitive data or even execute arbitrary code within the system. This poses a significant risk to organizations that use this software, as it can lead to data breaches, unauthorized system access, and other serious consequences. It is recommended that affected organizations apply the necessary patches or upgrades to address this vulnerability as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share