vendor:
Credit Lite
by:
CraCkEr
9.8
CVSS
CRITICAL
SQL Injection
89, 74, 707
CWE
Product Name: Credit Lite
Affected Version From: 1.5.2004
Affected Version To: 1.5.2004
Patch Exists: NO
Related CWE: CVE-2023-4407
CPE: a:hobby-tech:credit_lite:1.5.4
Platforms Tested: Windows 10 Pro
2023
Credit Lite 1.5.4 – SQL Injection
SQL injection attacks can allow unauthorized access to sensitive data, modification of data and crash the application or make it unavailable, leading to lost revenue and damage to a company's reputation.
Mitigation:
Implement proper input validation and parameterized queries to prevent SQL injection attacks.