CVE-2023-33439

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published May 26, 2023
Updated: Jan 14, 2025
CWE ID 89

Summary

CVE-2023-33439: Sourcecodester's Faculty Evaluation System version 1.0 suffers from an SQL injection vulnerability. Malicious users can exploit this weakness by manipulating the 'id' parameter in the /eval/admin/manage_task.php?id= URL, potentially gaining unauthorized access to sensitive data or even taking control of the system. This issue poses a significant risk to organizations using this outdated software and urgently requires a patch or upgrade to a secure version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share