CVE-2023-49639

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 4, 2024
Updated: Jan 10, 2024
CWE ID 89

Summary

CVE-2023-49639: The billing software version 1.0 contains unauthenticated SQL injection vulnerabilities. These vulnerabilities affect the 'customer_details' parameter in the buyer_invoice_submit.php resource, allowing attackers to inject malicious SQL commands into the database without proper validation, potentially leading to unauthorized data access or modification. This issue poses a significant risk to organizations using this software and requires immediate attention and patches to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share