CVE Published: 28/09/2023 |
CVE Updated: 23/09/2024 |
CVE Year: 2023 Source: Fluid Attacks |
Vendor: Asset Management System |
Product: Asset Management System Status : PUBLISHED
CVE-2023-43013 Description
Asset Management System v1.0 is vulnerable to an
unauthenticated SQL Injection vulnerability on the
\'email\' parameter of index.php page, allowing an
external attacker to dump all the contents of the
database contents and bypass the login control.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H