CVE-2023-5023

CVSS V2 None CVSS V3 None
Description
A vulnerability was found in Tongda OA 2017 and classified as critical. Affected by this issue is some unknown functionality of the file general/hr/manage/staff_relatives/delete.php. The manipulation of the argument RELATIVES_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239864.
Overview
  • CVE ID
  • CVE-2023-5023
  • Assigner
  • VulDB
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-17T06:00:10.673Z
  • Last Modified Date
  • 2023-10-24T19:07:14.827Z
References
Reference URL Reference Tags
https://vuldb.com/?id.239864 vdb-entry technical-description
https://vuldb.com/?ctiid.239864 signature permissions-required
https://github.com/RCEraser/cve/blob/main/sql_inject_3.md exploit
History
Created Old Value New Value Data Type Notes
2024-06-25 05:28:53 Added to TrackCVE