WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and password parameters. Attackers can inject malicious SQL queries using techniques like OR '1'='1' and stacked queries to access database information or execute administrative commands.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-13 23:16
Updated : 2026-01-14 16:25
NVD link : CVE-2023-54340
Mitre link : CVE-2023-54340
CVE.ORG link : CVE-2023-54340
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
