CVE-2023-40956

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 15, 2023
Updated: Sep 19, 2023
CWE ID 89

Summary

CVE-2023-40956 is a SQL injection vulnerability affecting Cloudroits Website Job Search version 15.0. A remote, authenticated attacker can exploit this issue by manipulating the name parameter in controllers/main.py to execute arbitrary code. This vulnerability poses a serious threat, allowing unauthorized code execution with the privileges of the affected component. Successful exploitation could result in data theft, unauthorized system access, or other malicious activities. It is crucial for users to update their software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share