Beveiligingsadvies

CVE-2023-44481

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-12-21 18:58:20
Laatst bijgewerkt 2024-09-12 19:52:52
Toegewezen door Fluid Attacks
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.