Asset Management System v1.0 is vulnerable to

an Authenticated SQL Injection vulnerability

on the 'first_name' and 'last_name' parameters

of user.php page, allowing an authenticated

attacker to dump all the contents of the database

contents.



Advisories
Source ID Title
EUVD EUVD EUVD-2023-47435 Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 23 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2024-09-23T18:48:41.280Z

Reserved: 2023-09-14T19:53:08.871Z

Link: CVE-2023-43014

cve-icon Vulnrichment

Updated: 2024-08-02T19:37:22.509Z

cve-icon NVD

Status : Modified

Published: 2023-09-28T22:15:10.203

Modified: 2024-11-21T08:23:37.560

Link: CVE-2023-43014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses