Unrated severityNVD Advisory· Published Jan 4, 2024· Updated Jun 17, 2025
Billing Software v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-49624
Description
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent unfiltered to the database.
Affected products
1- Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- fluidattacks.com/advisories/zimerman/mitrethird-party-advisory
- www.kashipara.commitreproduct
News mentions
0No linked articles in our index yet.