Vulnerability Description
SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id parameter in the login.php
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tianchoy | Blog | 1.8.8 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Chiaki2333/59ef607c3eb3a7b4db1537705d05e4d1Third Party Advisory
- https://github.com/Chiaki2333/vulnerability/blob/main/tianchoy-blog-sql-login.phExploitThird Party Advisory
- https://gist.github.com/Chiaki2333/59ef607c3eb3a7b4db1537705d05e4d1Third Party Advisory
- https://github.com/Chiaki2333/vulnerability/blob/main/tianchoy-blog-sql-login.phExploitThird Party Advisory
FAQ
What is CVE-2023-43381?
CVE-2023-43381 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id parameter in the login.php
How severe is CVE-2023-43381?
CVE-2023-43381 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43381?
Check the references section above for vendor advisories and patch information. Affected products include: Tianchoy Blog.