PT-2023-30515 · Unknown · Oss Calendar
Shogo Iyota
·
Published
2023-11-13
·
Updated
2023-11-17
·
CVE-2023-47609
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OSS Calendar versions prior to 2.0.3
Description
The issue allows a remote authenticated attacker to execute arbitrary code or obtain and/or alter the information stored in the database by sending a specially crafted request. This can be achieved through SQL injection.
Recommendations
For OSS Calendar versions prior to 2.0.3, update to version 2.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the database and limiting the privileges of authenticated users to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oss Calendar