code-projects Simple Art Gallery adminHome.php sql injection
CVE-2023-1499

9.8CRITICAL

Key Information:

Vendor
CVE Published:
19 March 2023

Summary

A significant SQL injection vulnerability has been identified in version 1.0 of Simple Art Gallery by Code-Projects. An issue in the adminHome.php file allows attackers to manipulate the 'reach_city' parameter, potentially compromising the database. This issue can be exploited remotely, exposing the application to data breaches and unauthorized access. Publicly disclosed exploits may be utilized by malicious actors, emphasizing the urgent need for remediation. Users of this product should prioritize patching and consulting security best practices to mitigate associated risks.

Affected Version(s)

Simple Art Gallery 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ChengFei (VulDB User)
.
CVE-2023-1499 : code-projects Simple Art Gallery adminHome.php sql injection | SecurityVulnerability.io