code-projects Simple Art Gallery adminHome.php sql injection
CVE-2023-1499
9.8CRITICAL
Summary
A significant SQL injection vulnerability has been identified in version 1.0 of Simple Art Gallery by Code-Projects. An issue in the adminHome.php file allows attackers to manipulate the 'reach_city' parameter, potentially compromising the database. This issue can be exploited remotely, exposing the application to data breaches and unauthorized access. Publicly disclosed exploits may be utilized by malicious actors, emphasizing the urgent need for remediation. Users of this product should prioritize patching and consulting security best practices to mitigate associated risks.
Affected Version(s)
Simple Art Gallery 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ChengFei (VulDB User)