Beveiligingsadvies

CVE-2023-44480

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-10-27 20:52:46
Laatst bijgewerkt 2024-09-09 17:14:16
Toegewezen door Fluid Attacks
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.