CVE-2023-7145

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 29, 2023
Updated: May 17, 2024
CWE ID 89

Summary

CVE-2023-7145 is a critical vulnerability affecting gopeak MasterLab up to version 3.3.10. The issue lies in the sqlInject function of the File app/ctrl/Framework.php, within the HTTP POST Request Handler component. Manipulation of the argument pwd results in sql injection, making the system susceptible to malicious queries. This vulnerability has been publicly disclosed and exploited, increasing the risk for potential attacks. The identifier for this issue is VDB-249148.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share