PT-2025-20802 · Billing · Billing

Published

2025-05-12

·

Updated

2025-05-18

·

CVE-2023-49641

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Billing Software version 1.0
Description The issue concerns multiple Unauthenticated SQL Injection vulnerabilities. Specifically, the username parameter of the "loginCheck.php" resource does not validate the characters received and they are sent unfiltered to the database. This lack of validation allows for potential SQL injection attacks.
Recommendations For Billing Software version 1.0, as a temporary workaround, consider validating and filtering the username parameter in the loginCheck.php resource to prevent SQL injection attacks. Restrict access to the loginCheck.php resource until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-49641

Affected Products

Billing