First published: Thu Sep 28 2023(Updated: )
Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.
Credit: help@fluidattacks.com help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Asset Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-43014.
The severity of CVE-2023-43014 is high.
The affected software for CVE-2023-43014 is Projectworlds Asset Management System v1.0.
The impact of CVE-2023-43014 is an authenticated attacker can dump all the contents of the database.
To fix CVE-2023-43014, you should follow the official security advisory and patch the vulnerability as soon as possible.