28Ara
CVE-2023-7144 | gopeak MasterLab up to 3.3.10 HTTP POST Request Feature.php sqlInject pwd sql injection
A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the functionsqlInject
of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection.
This vulnerability is uniquely identified as CVE-2023-7144. The attack needs to be done within the local network. Furthermore, there is an exploit available.