Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:webtareas_project:webtareas:2.4:p3:*:*:*:*:*:* |
Sat, 27 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 26 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webtareas Project
Webtareas Project webtareas |
|
| CPEs | cpe:2.3:a:webtareas_project:webtareas:2.4:-:*:*:*:*:*:* | |
| Vendors & Products |
Webtareas Project
Webtareas Project webtareas |
Mon, 22 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploit error-based and time-based blind SQL injection techniques to extract database information and potentially access sensitive system data. | |
| Title | WebTareas 2.4 Unauthenticated SQL Injection via Session Cookie Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:08:15.099Z
Reserved: 2025-12-20T16:31:20.898Z
Link: CVE-2023-53972
Updated: 2025-12-22T21:58:45.425Z
Status : Modified
Published: 2025-12-22T22:16:02.280
Modified: 2025-12-27T17:15:45.230
Link: CVE-2023-53972
No data.
OpenCVE Enrichment
No data.