PT-2024-13452 · Reportico · Reportico

Aashiqahamedno

·

Published

2024-03-27

·

Updated

2024-09-04

·

CVE-2023-47438

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Reportico versions prior to 8.1.0
Description The issue allows attackers to obtain sensitive information or other system information via the project parameter. This is a SQL Injection vulnerability, which means attackers can inject malicious SQL code to manipulate the database and extract or modify sensitive data.
Recommendations For versions prior to 8.1.0, update to version 8.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the project parameter to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47438
GHSA-JJF4-959W-F545

Affected Products

Reportico