CVE-2023-31938

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Aug 17, 2023
Updated: Aug 18, 2023
CWE ID 89

Summary

CVE-2023-31938 represents a significant security risk, as it allows remote attackers to exploit an SQL injection vulnerability present in the employee_detail.php file of the Online Travel Agency System v.1.0. By inputting maliciously crafted data into the emp_id parameter, an attacker can execute arbitrary code, potentially leading to unauthorized access, data theft, or system damage. This vulnerability underscores the importance of proper input validation and sanitization to prevent such attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share