First published: Sun Sep 17 2023(Updated: )
A vulnerability has been found in Tongda OA up to 11.10 and classified as critical. This vulnerability affects unknown code of the file general/hr/recruit/plan/delete.php. The manipulation of the argument PLAN_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239872.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tongda2000 Tongda Oa | <=11.10 | |
<=11.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5030 is classified as high.
Tongda OA up to version 11.10 is affected by CVE-2023-5030.
The CWE category of CVE-2023-5030 is CWE-89 (SQL Injection).
To fix CVE-2023-5030, it is recommended to update Tongda OA to a version that is no longer affected by this vulnerability and apply any available patches or fixes provided by the vendor.
Yes, an exploit for CVE-2023-5030 has been disclosed to the public and may be used.