CVE-2023-43014: Asset Management System v1.0 - Authenticated SQL Injection (SQLi)
Published Sep 28, 2023
·Updated
Asset Management System v1.0 is vulnerable to
an Authenticated SQL Injection vulnerability
on the 'firstname' and 'lastname' parameters
of user.php page, allowing an authenticated
attacker to dump all the contents of the database
contents.
Affected Software
1 affected component
Projectworlds Asset Management System=1.0
Event History
Sep 28, 2023
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-43014.
2
What is the severity of CVE-2023-43014?
The severity of CVE-2023-43014 is high.
3
What is the affected software for CVE-2023-43014?
The affected software for CVE-2023-43014 is Projectworlds Asset Management System v1.0.
4
What is the impact of CVE-2023-43014?
The impact of CVE-2023-43014 is an authenticated attacker can dump all the contents of the database.
5
How can I fix CVE-2023-43014?
To fix CVE-2023-43014, you should follow the official security advisory and patch the vulnerability as soon as possible.