CVE-2023-22630

IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.
Configurations

Configuration 1 (hide)

cpe:2.3:a:izybat:orange_casiers:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
Summary
  • (es) Los casiers IzyBat Orange anteriores a 20221102_1 permiten la inyección de SQL a través de un URI getCasier.php?taille=.
References () https://github.com/orangecertcc/security-research/security/advisories/GHSA-j94f-5cg6-6j9j - Exploit, Third Party Advisory () https://github.com/orangecertcc/security-research/security/advisories/GHSA-j94f-5cg6-6j9j - Exploit, Third Party Advisory

Information

Published : 2023-01-23 22:15

Updated : 2025-04-02 16:15


NVD link : CVE-2023-22630

Mitre link : CVE-2023-22630

CVE.ORG link : CVE-2023-22630


JSON object : View

Products Affected

izybat

  • orange_casiers
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')