← Back to CVE List

CVE-2023-49622

Published: 2024-01-04T14:15Z
Last Modified: 2024-11-21T08:33Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and they are sent unfiltered to the database. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt