CVE-2023-24651: XSS
Published Feb 27, 2023
·Updated
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.
Affected Software
2 affected components
Simple Customer Relationship Management System Project Simple Customer Relationship Management System=1.0
oretnom23 Simple Customer Relationship Management System=1.0
Event History
Feb 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24651?
CVE-2023-24651 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2023-24651?
To fix CVE-2023-24651, you should validate and sanitize the 'name' parameter on the registration page to prevent SQL injection.
3
What systems are affected by CVE-2023-24651?
CVE-2023-24651 affects version 1.0 of the Simple Customer Relationship Management System.
4
Can CVE-2023-24651 lead to data breaches?
Yes, CVE-2023-24651 can lead to data breaches by allowing attackers to execute arbitrary SQL queries.
5
Is it safe to use Simple Customer Relationship Management System v1.0 after CVE-2023-24651?
It is not safe to use Simple Customer Relationship Management System v1.0 until the vulnerability CVE-2023-24651 has been addressed.