CVE-2023-27742: SQL Injection
Published May 16, 2023
·Updated
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
Affected Software
2 affected components
Idurar Project Idurar=1.0.0
Idurarapp Idurar=1.0.0
Event History
May 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-27742?
CVE-2023-27742 is classified as a high severity SQL injection vulnerability affecting IDURAR ERP/CRM v1.0.0.
2
How do I fix CVE-2023-27742?
To fix CVE-2023-27742, sanitize and validate all input fields in the /api/login component to prevent SQL injection.
3
What components are affected by CVE-2023-27742?
CVE-2023-27742 affects the Idurar Project and Idurarapp versions 1.0.0.
4
What kind of attack can be performed using CVE-2023-27742?
An attacker can exploit CVE-2023-27742 to execute arbitrary SQL commands in the database via the /api/login API.
5
Is there a patch available for CVE-2023-27742?
As of now, confirm with the vendor if a patch is available or implement recommended security practices to mitigate the vulnerability.