CVE-2023-48823: SQL Injection
Published Dec 7, 2023
·Updated
A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login.
Affected Software
1 affected component
Mayurik Courier Management System=1.0
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-48823.
2
What is the severity of CVE-2023-48823?
The severity of CVE-2023-48823 is critical.
3
What is GaatiTrack Courier Management System affected version?
GaatiTrack Courier Management System version 1.0 is affected.
4
How does the vulnerability exploit work?
The vulnerability allows an unauthenticated attacker to perform Blind SQL injection by injecting a payload via the 'email' parameter during login.
5
Is there a fix available for this vulnerability?
Currently, there is no known fix available for this vulnerability. It is recommended to follow best security practices and consider upgrading to a patched version if one becomes available.