CVE-2023-24729: SQL Injection
Published Mar 15, 2023
·Updated
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
Affected Software
2 affected components
Simple Customer Relationship Management System Project Simple Customer Relationship Management System=1.0
oretnom23 Simple Customer Relationship Management System=1.0
Event History
Mar 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24729?
CVE-2023-24729 has been classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2023-24729?
To fix CVE-2023-24729, sanitize and parameterize user inputs in the address parameter to prevent SQL injection.
3
What attack vector is associated with CVE-2023-24729?
The attack vector for CVE-2023-24729 is through the user profile update function, specifically manipulating the address parameter.
4
What are the potential impacts of CVE-2023-24729?
Exploitation of CVE-2023-24729 could allow unauthorized access to sensitive data or lead to a database compromise.
5
Is CVE-2023-24729 specific to certain software versions?
Yes, CVE-2023-24729 specifically affects version 1.0 of the Simple Customer Relationship Management System.