CVE-2023-40956
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-40956 is a SQL injection vulnerability affecting Cloudroits Website Job Search version 15.0. A remote, authenticated attacker can exploit this issue by manipulating the name parameter in controllers/main.py to execute arbitrary code. This vulnerability poses a serious threat, allowing unauthorized code execution with the privileges of the affected component. Successful exploitation could result in data theft, unauthorized system access, or other malicious activities. It is crucial for users to update their software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.