CVE-2023-46956: SQL Injection
SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manageuser&id file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46956?
CVE-2023-46956 is a SQL injection vulnerability found in Packers and Movers Management System v.1.0.
How does the SQL injection vulnerability in Packers and Movers Management System v.1.0 work?
The SQL injection vulnerability allows a remote attacker to execute arbitrary code by sending a crafted payload to the /mpms/admin/?page=user/manage_user&id file.
What is the severity of CVE-2023-46956?
CVE-2023-46956 has a severity rating of 7.2 (high).
How can the SQL injection vulnerability in Packers and Movers Management System v.1.0 be exploited?
The SQL injection vulnerability can be exploited by an attacker sending a crafted payload to the /mpms/admin/?page=user/manage_user&id file.
Is there a fix available for CVE-2023-46956?
To fix CVE-2023-46956, it is recommended to update Packers and Movers Management System to a version that has patched the SQL injection vulnerability.