CVE-2023-33592
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.8%
from disclosure to weapon8 days
Published on NVDJun 28
1st PoC+8d
exploitation probability
3.8%top 11% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/51570unverifiedgithubgithub.com/ChineseOldboy/CVE-2023-33592★ 1cve_referencepacketstormsecurity.com/files/173331/Lost-And-Found-Information-System-1.0-SQL-Injection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/173331/Lost-And-Found-Information-System-1.0-SQL-Injection.htmlhttps://github.com/DARSHANAGUPTA10/CVE/blob/main/CVE-2023-33592https://www.sourcecodester.com/php/16525/lost-and-found-information-system-using-php-and-mysql-db-source-code-free-download.html