Vulnerability Description
Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Online Art Gallery | 1.0 |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/onoExploitThird Party Advisory
- https://https://projectworlds.in/Broken Link
- https://fluidattacks.com/advisories/onoExploitThird Party Advisory
- https://https://projectworlds.in/Broken Link
FAQ
What is CVE-2023-44267?
CVE-2023-44267 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are s...
How severe is CVE-2023-44267?
CVE-2023-44267 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-44267?
Check the references section above for vendor advisories and patch information. Affected products include: Projectworlds Online Art Gallery.