Description
Asset Management System v1.0 is vulnerable to

an Authenticated SQL Injection vulnerability

on the 'first_name' and 'last_name' parameters

of user.php page, allowing an authenticated

attacker to dump all the contents of the database

contents.



Published: 2023-09-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-47435 Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.
History

Mon, 23 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Projectworlds Asset Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2024-09-23T18:48:41.280Z

Reserved: 2023-09-14T19:53:08.871Z

Link: CVE-2023-43014

cve-icon Vulnrichment

Updated: 2024-08-02T19:37:22.509Z

cve-icon NVD

Status : Modified

Published: 2023-09-28T22:15:10.203

Modified: 2024-11-21T08:23:37.560

Link: CVE-2023-43014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses