CVE-2023-7145
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 29, 2023
Updated: May 17, 2024
CWE ID 89
Summary
CVE-2023-7145 is a critical vulnerability affecting gopeak MasterLab up to version 3.3.10. The issue lies in the sqlInject function of the File app/ctrl/Framework.php, within the HTTP POST Request Handler component. Manipulation of the argument pwd results in sql injection, making the system susceptible to malicious queries. This vulnerability has been publicly disclosed and exploited, increasing the risk for potential attacks. The identifier for this issue is VDB-249148.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.