CVE-2023-49633
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 4, 2024
Updated: Jan 10, 2024
CWE ID 89
Summary
CVE-2023-49633: Billing Software v1.0 contains unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter in the 'buyer_detail_submit.php' resource fails to validate user input, allowing attackers to inject malicious SQL queries into the database without authentication. This issue poses a serious risk of data leakage or unauthorized access. Users are advised to patch or upgrade their software as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- billing software