Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Zhuchangxing

#24223de 53,638
9.8CVSS total
Vulnerabilidades · 1
PT-2023-32838
9.8
2023-12-20
Tongda Oa · Tongda Oa · CVE-2023-7021
**Name of the Vulnerable Software and Affected Versions** Tongda OA 2017 versions up to 11.9 **Description** A critical issue has been found in the software, affecting an unknown function of the file general/vehicle/checkup/delete search.php. The manipulation of the `VU ID` argument leads to sql injection, allowing for remote attacks. The issue has been publicly disclosed and may be exploited. **Recommendations** For Tongda OA 2017 versions up to 11.9, upgrade to version 11.10 to address this issue. As a temporary workaround, consider restricting access to the `delete search.php` file until the upgrade is applied.