First published: Mon Nov 13 2023(Updated: )
SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Code-Projects Blood Bank | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2023-46021.
The severity rating of CVE-2023-46021 is medium with a severity value of 5.5.
The affected software for CVE-2023-46021 is Code-Projects Blood Bank 1.0.
An attacker can exploit CVE-2023-46021 by running arbitrary commands through the 'reqid' parameter in cancel.php.
To fix CVE-2023-46021, it is recommended to apply the latest patch or update from the software vendor.