Beveiligingsadvies

CVE-2023-46789

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-11-07 21:02:14
Laatst bijgewerkt 2024-09-17 13:05:41
Toegewezen door Fluid Attacks
CVSS-score 9.8
Status PUBLISHED

Beschrijving

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic1' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.