CRITICAL
Tongda OA delete.php sql injection
Published Oct 20, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.67%
Description
A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/training/record/delete.php. The manipulation of the argument RECORD_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-243058 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 2017StatusaffectedConstraints-
- Version
OR
- < 11.10
- 2017
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57973 Advisory
- https://github.com/Godfather-onec/cve/blob/main/sql.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.243058 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.243058 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57973 | Advisory | |
| https://github.com/Godfather-onec/cve/blob/main/sql.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.243058 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.243058 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Oct 20, 2023
Updated Oct 11, 2024
Reserved Oct 20, 2023
Link CVE-2023-5682
CISA Vulnrichment
Updated Oct 11, 2024
ENISA EUVD
EUVD-2023-57973 Assigner VulDB
Published Oct 20, 2023
Updated Oct 11, 2024
Exploited since n/a
Link EUVD-2023-57973