CVE-2023-46789

CRITICAL

Online Matrimonial Project v1.0 - SQL Injection

Title source: llm
STIX 2.1

Description

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'filename' attribute of the 'pic1' multipart parameter of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

References (2)

Core 2
Core References
Exploit, Third Party Advisory third-party-advisory
https://fluidattacks.com/advisories/ros

Scores

CVSS v3 9.8
EPSS 0.0014
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
projectworlds/online_matrimonial_project 1.0
Published Nov 07, 2023
Tracked Since Feb 18, 2026