CVE-2023-46018
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Nov 13, 2023
Updated: Nov 16, 2023
CWE ID 89
Summary
CVE-2023-46018 is a newly discovered SQL injection vulnerability that affects the Code-Projects Blood Bank 1.0 software. The issue lies in the receiverReg.php file, where the 'remail' parameter is susceptible to malicious SQL injection attacks. Successful exploitation of this vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized access, data theft, or system compromise. Organizations using this software version are advised to apply the necessary patches or updates as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Code Projects