CVE-2023-6074
published 2023-11-10CVE-2023-6074: A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.70%
48.7th percentile
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | >= 0 < 113.0.1+build1-0ubuntu0.18.04.1 | 113.0.1+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 113.0.2+build1-0ubuntu0.18.04.1 | 113.0.2+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 113.0.1+build1-0ubuntu0.20.04.1 | 113.0.1+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= 0 < 113.0.2+build1-0ubuntu0.20.04.1 | 113.0.2+build1-0ubuntu0.20.04.1 |
| phpgurukul | restaurant_table_booking_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2p35-56jw-vgq5: A vulnerability was found in PHPGurukul Restaurant Table Booking System 1
ghsa_unreviewed·2023-11-10
CVE-2023-6074 [MEDIUM] CWE-89 GHSA-2p35-56jw-vgq5: A vulnerability was found in PHPGurukul Restaurant Table Booking System 1
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file check-status.php of the component Booking Reservation Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-244943.
OSV
firefox regressions
osv·2023-05-24·CVSS 4.3
firefox regressions
firefox regressions
USN-6074-1 fixed vulnerabilities and USN-6074-2 fixed minor regressions in
Firefox. The update introduced several minor regressions. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-32205,
CVE-2023-32207, CVE-2023-32210, CVE-2023-32211, CVE-2023-32212,
CVE-2023-32213, CVE-2023-32215, CVE-2023-32216)
Irvan Kurniawan discovered that Firefox did not properly manage memory
when using RLBox Expat driver. An attacker could potentially exploits this
issue to
OSV
firefox regressions
osv·2023-05-16·CVSS 4.3
CVE-2023-32205 firefox regressions
firefox regressions
USN-6074-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-32205,
CVE-2023-32207, CVE-2023-32210, CVE-2023-32211, CVE-2023-32212,
CVE-2023-32213, CVE-2023-32215, CVE-2023-32216)
Irvan Kurniawan discovered that Firefox did not properly manage memory
when using RLBox Expat driver. An attacker could potentially exploits this
issue to cause a denial of service. (CVE-2023-32
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-11-10
Published