CVE-2023-43013: Asset Management System v1.0 - Unauthenticated SQL Injection (SQLi)
Asset Management System v1.0 is vulnerable to an
unauthenticated SQL Injection vulnerability on the
'email' parameter of index.php page, allowing an
external attacker to dump all the contents of the
database contents and bypass the login control.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-43013.
What is the severity of CVE-2023-43013?
The severity of CVE-2023-43013 is critical, with a CVSS score of 9.8.
How does CVE-2023-43013 affect Asset Management System v1.0?
CVE-2023-43013 affects Asset Management System v1.0 by exposing an unauthenticated SQL Injection vulnerability on the 'email' parameter of the index.php page.
What is the impact of CVE-2023-43013?
The impact of CVE-2023-43013 is that it allows an external attacker to dump all the contents of the database and bypass the login control.
How can the vulnerability in Asset Management System v1.0 be fixed?
To fix the vulnerability in Asset Management System v1.0, it is recommended to update to a patched version or apply the necessary security patches provided by the vendor.