First published: Fri Sep 29 2023(Updated: )
A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/recruit/hr_pool/delete.php. The manipulation of the argument EXPERT_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-240880.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tongda2000 Tongda Oa | <11.10 | |
Tongda2000 Tongda Oa | =2017 | |
<11.10 | ||
=2017 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5267 is critical.
Tongda OA versions up to 11.10 and Tongda OA 2017 are affected by CVE-2023-5267.
CVE-2023-5267 belongs to the CWE category 89.
CVE-2023-5267 can lead to SQL injection by manipulating the EXPERT_ID parameter in the file general/hr/recruit/hr_pool/delete.php of Tongda OA 2017.
Currently, there is no known fix for CVE-2023-5267. It is recommended to apply vendor patches or upgrades when they become available.