CVE-2023-43013
Asset Management System v1.0 - Unauthenticated SQL Injection (SQLi)
Asset Management System v1.0 is vulnerable to an
unauthenticated SQL Injection vulnerability on the
'email' parameter of index.php page, allowing an
external attacker to dump all the contents of the
database contents and bypass the login control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Asset Management System · Asset Management SystemWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →