CVE-2023-40921

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 14, 2023
Updated: Dec 18, 2023
CWE ID 89

Summary

CVE-2023-40921 is a newly discovered SQL Injection vulnerability affecting the functions/point_list.php file in Common Services soliberte versions prior to 4.3.03. This issue grants malicious actors the ability to extract sensitive information by manipulating the lat and lng parameters. Successful exploitation could lead to significant data leaks, posing a serious risk to system security. Users are urged to update their installations as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share