CVE-2023-43013
Asset Management System v1.0 - Unauthenticated SQL Injection (SQLi)
Asset Management System v1.0 is vulnerable to an
unauthenticated SQL Injection vulnerability on the
'email' parameter of index.php page, allowing an
external attacker to dump all the contents of the
database contents and bypass the login control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Asset Management System · Asset Management System¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →