CVE-2023-45503
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.
Vulnerabilidad de inyección SQL en Macrob7 Macs CMS 1.1.4f, permite a atacantes remotos ejecutar código arbitrario, provocar una denegación de servicio (DoS), escalar privilegios y obtener información confidencial a través de un payload manipulado para resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-10-09 CVE Reserved
- 2024-04-11 First Exploit
- 2024-04-15 CVE Published
- 2024-04-16 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://docs.google.com/spreadsheets/d/1AzXspN8oBAJ80YQxfN44bpbOuNzA3PZEccQ6IGQMs5E/edit?usp=sharing | ||
https://github.com/ally-petitt/CVE-2023-45503?tab=readme-ov-file |
URL | Date | SRC |
---|---|---|
https://github.com/ally-petitt/CVE-2023-45503 | 2024-04-11 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Macrob7 Macs Framework Content Management System Project Search vendor "Macrob7 Macs Framework Content Management System Project" | Macrob7 Macs Framework Content Management System Search vendor "Macrob7 Macs Framework Content Management System Project" for product "Macrob7 Macs Framework Content Management System" | * | - |
Affected
|