CVE-2023-24654: SQL Injection
Published Feb 27, 2023
·Updated
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.
Affected Software
2 affected components
Simple Customer Relationship Management System Project Simple Customer Relationship Management System=1.0
oretnom23 Simple Customer Relationship Management System=1.0
Event History
Feb 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24654?
CVE-2023-24654 has been classified with a high severity level due to its SQL injection vulnerability.
2
How do I fix CVE-2023-24654?
To fix CVE-2023-24654, validate and sanitize user inputs, especially the 'name' parameter in the Request a Quote function.
3
What systems are affected by CVE-2023-24654?
CVE-2023-24654 affects Simple Customer Relationship Management System version 1.0.
4
Can CVE-2023-24654 lead to data leakage?
Yes, CVE-2023-24654 can potentially allow attackers to execute unauthorized SQL queries, leading to data leakage.
5
Is there a patch available for CVE-2023-24654?
Currently, there is no official patch available for CVE-2023-24654, so immediate mitigation through input validation is necessary.