Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Hugo Vovard

Pesquisador deOrange group
#50969de 53,632
4.3CVSS total
Vulnerabilidades · 1
PT-2023-18598
4.3
2023-01-23
Unknown · Izybat Orange Casiers · CVE-2023-22630
**Name of the Vulnerable Software and Affected Versions** IzyBat Orange casiers versions before 20221102 1 **Description** The issue allows SQL Injection via a "getCasier.php?taille=" URI. **Recommendations** For versions before 20221102 1, update to a version 20221102 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "getCasier.php" endpoint until a patch is available. Avoid using the `taille` parameter in the affected API endpoint until the issue is resolved.