CVE-2023-48893: SQL Injection
SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staffact.php SQL Injection via startDate or untilDate.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-48893?
CVE-2023-48893 is a SQL injection vulnerability in Senayan Library Management Systems Slims 9 Bulian v.9.6.1.
How does CVE-2023-48893 affect the software?
CVE-2023-48893 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the date parameter in the staff_act.php file.
What is the severity of CVE-2023-48893?
CVE-2023-48893 has a severity rating of 8.8 (high).
How can I fix CVE-2023-48893?
To fix CVE-2023-48893, you should update your Senayan Library Management Systems Slims to a version that has patched the SQL injection vulnerability.
Where can I find more information about CVE-2023-48893?
You can find more information about CVE-2023-48893 on the GitHub links provided: [GitHub Issue](https://github.com/slims/slims9_bulian/issues/209) and [GitHub Advisory](https://github.com/Vuln0wned/slims_owned/blob/main/slims/slims9-bulian-9.6.1-SQLI-staff_act.md).