CVE-2023-40970: SQL Injection
Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loanrules.php.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-40970.
What is the severity of CVE-2023-40970?
The severity of CVE-2023-40970 is high with a severity score of 8.8.
What is the affected software?
The affected software is Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability through SQL Injection via the 'loan_rules.php' module in the 'circulation' directory of the 'admin' module.
Are there any references or resources available for CVE-2023-40970?
Yes, you can refer to the following links for more information: [GitHub - komangsughosa/CVE-ID-not-yet](https://github.com/komangsughosa/CVE-ID-not-yet/blob/main/slims/slims9_bulian-9.6.1-SQLI-loan_rules.md) and [GitHub - slims/slims9_bulian/issues/205](https://github.com/slims/slims9_bulian/issues/205).