First published: Fri Sep 29 2023(Updated: )
A vulnerability, which was classified as critical, was found in Tongda OA 2017. Affected is an unknown function of the file general/hr/manage/staff_title_evaluation/delete.php. The manipulation of the argument EVALUATION_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240870 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tongda2000 Tongda Oa | <11.10 | |
Tongda2000 Tongda Oa | =2017 | |
<11.10 | ||
=2017 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5261 is critical with a severity value of 9.8.
The affected software of CVE-2023-5261 is Tongda OA 2017.
The vulnerability type of CVE-2023-5261 is SQL injection.
By manipulating the EVALUATION_ID argument in delete.php, an attacker can inject malicious SQL queries into the database, potentially gaining unauthorized access or manipulating data.
More information about CVE-2023-5261 can be found at the following references: [Reference 1](https://github.com/csbsong/bug_report/blob/main/sql2.md), [Reference 2](https://vuldb.com/?ctiid.240870), [Reference 3](https://vuldb.com/?id.240870).