First published: Thu Oct 26 2023(Updated: )
A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /manage/delete_query.php of the component General News. The manipulation of the argument NEWS_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243588. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
<11.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5782 is critical.
The affected software of CVE-2023-5782 is Tongda OA 2017 up to version 11.10.
The CWE ID for CVE-2023-5782 is 89.
To fix the SQL injection vulnerability in Tongda OA 2017, you should apply the latest updates and patches provided by the vendor Tongda2000.
You can find more information about CVE-2023-5782 on VulDB (https://vuldb.com/?id.243588) and GitHub (https://github.com/Charmeeeeee/Tongda-OA-repo/blob/main/Tongda_OA_Vulnerability_Report.md).