CVE-2023-43371

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 20, 2023
Updated: Sep 21, 2023
CWE ID 89

Summary

CVE-2023-43371 is a newly discovered SQL injection vulnerability affecting Hoteldruid v3.0.5. The issue lies within the creaprezzi.php file, specifically the numcaselle parameter. An attacker can exploit this vulnerability by injecting malicious SQL code, potentially gaining unauthorized access to sensitive data or making unintended modifications to the database. This type of attack can lead to significant security risks and potential data breaches, emphasizing the importance of applying the necessary patch or update as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share