CVE-2023-46018

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 13, 2023
Updated: Nov 16, 2023
CWE ID 89

Summary

CVE-2023-46018 is a newly discovered SQL injection vulnerability that affects the Code-Projects Blood Bank 1.0 software. The issue lies in the receiverReg.php file, where the 'remail' parameter is susceptible to malicious SQL injection attacks. Successful exploitation of this vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized access, data theft, or system compromise. Organizations using this software version are advised to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share