code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_form sql injection
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Creation Endpoint. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
code-projects · Matrimonial Systempublic PoCs found — 1
cve_referencegithub.com/KaranParelkar/Matrimonial_system_sqli/blob/main/sqli_createprofile/fname_parameter/Readme.mdunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.