SQL Injection Vulnerability in Art Gallery Management System by Anky
CVE-2023-37771
9.8CRITICAL
Summary
The Art Gallery Management System version 1.0 is susceptible to a SQL injection vulnerability through the 'cid' parameter in the /agms/product.php endpoint. An attacker can exploit this weakness to execute arbitrary SQL commands that could lead to unauthorized data access or manipulation, compromising the integrity and confidentiality of the system's database. Protecting against such vulnerabilities is critical for the security of web applications, and it is advised to validate and sanitize user inputs effectively.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database0 Proof of Concept(s)