CRITICAL🇵🇱 Wersja polska

CVE-2023-3490

CVSS 9.8v3.1pub. 2023-06-30upd. 2024-11-21

SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fossbilling

    APP
    Fossbilling
    < 0.5.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2023-4005CRITICAL9.8PL ✓same product

Niewystarczające wygasanie sesji w FOSSBilling (przed wersją 0.5.5)

CVE-2023-3491HIGH8.8same product

Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVE-2023-3493HIGH8.0same product

Improper Neutralization of Formula Elements in a CSV File in GitHub repository fossbilling/fossbilling prior t...

CVE-2023-3393HIGH7.2same product

Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

CVE-2023-3230HIGH7.5same product

Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.