PT-2023-32643 · Unknown · Voovi Social Networking Script

·

CVE-2023-6412

·

Published

2023-11-30

·

Updated

2023-12-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Voovi Social Networking Script version 1.0
Description A SQL injection vulnerability has been reported in Voovi Social Networking Script, affecting the photo.php file with multiple parameters. This could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.
Recommendations For version 1.0, consider restricting access to the photo.php file until a patch is available. As a temporary workaround, avoid using the vulnerable parameters in the photo.php file to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6412

Affected Products

Voovi Social Networking Script