CVE-2023-24653: SQL Injection
Published Feb 27, 2023
·Updated
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.
Affected Software
2 affected components
Simple Customer Relationship Management System Project Simple Customer Relationship Management System=1.0
oretnom23 Simple Customer Relationship Management System=1.0
Event History
Feb 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24653?
CVE-2023-24653 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2023-24653?
To fix CVE-2023-24653, validate and sanitize user inputs in the Change Password function to prevent SQL injection.
3
What parts of Simple Customer Relationship Management System are affected by CVE-2023-24653?
CVE-2023-24653 affects the Change Password function, specifically the oldpass parameter.
4
What types of attacks can CVE-2023-24653 facilitate?
CVE-2023-24653 can facilitate unauthorized access and data manipulation through SQL injection attacks.
5
Is CVE-2023-24653 present in versions other than 1.0 of the Simple Customer Relationship Management System?
CVE-2023-24653 has been identified specifically in version 1.0 of the Simple Customer Relationship Management System.