CVE-2023-49641: Kashipara Group Billing Software

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent unfiltered to the database.

Affected products

Published 2025-05-13. Last modified 2026-06-17.