Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-54865
HistoryJul 04, 2023 - 12:00 a.m.

IBOS OA SQL Injection Vulnerability

2023-07-0400:00:00
China National Vulnerability Database
www.cnvd.org.cn
5
ibos
sql injection
version 4.5.5
validation
add user handler
attacker
sensitive data
database

EPSS

0.001

Percentile

46.1%

IBOS is a collaborative office management system. A SQL injection vulnerability exists in IBOS OA version 4.5.5, which originates from the lack of validation of the parameter id in the component Add User Handler against externally entered SQL statements, and can be exploited by an attacker to execute illegal SQL commands to steal sensitive database data.

EPSS

0.001

Percentile

46.1%

Related for CNVD-2023-54865