CVE-2023-53972
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
22/12/2025
Last modified:
27/12/2025
Description
WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploit error-based and time-based blind SQL injection techniques to extract database information and potentially access sensitive system data.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:webtareas_project:webtareas:2.4:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



