Vulnerability Description
Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Asset Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/gaahlExploitThird Party Advisory
- https://projectworlds.in/Product
- https://fluidattacks.com/advisories/gaahlExploitThird Party Advisory
- https://projectworlds.in/Product
FAQ
What is CVE-2023-43014?
CVE-2023-43014 is a vulnerability with a CVSS score of 8.8 (HIGH). Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to du...
How severe is CVE-2023-43014?
CVE-2023-43014 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43014?
Check the references section above for vendor advisories and patch information. Affected products include: Projectworlds Asset Management System.