CVE-2023-45015
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 2, 2023
Updated: Nov 8, 2023
CWE ID 89
Summary
CVE-2023-45018: The Online Bus Booking System version 1.0 contains multiple SQL injection vulnerabilities. These vulnerabilities are unauthenticated and affect the 'username' parameter in the includes/login.php resource. The input received through this parameter is not validated, allowing attackers to inject and execute malicious SQL queries, potentially leading to unauthorized access or data theft.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share