Back

CRITICAL

Online Notice Board System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

Published Jan 4, 2024

Description

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Jan 4, 2024
Updated Sep 5, 2024
Reserved Dec 12, 2023
CISA Vulnrichment
Updated Mar 12, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Fluid Attacks
Published Jan 4, 2024
Updated Sep 5, 2024
Exploited since n/a
EUVD-2023-55505