SQL Injection Vulnerability in Art Gallery Management System by Anky
CVE-2023-37771

9.8CRITICAL

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
31 July 2023

Badges

πŸ‘Ύ Exploit Exists

Summary

The Art Gallery Management System version 1.0 is susceptible to a SQL injection vulnerability through the 'cid' parameter in the /agms/product.php endpoint. An attacker can exploit this weakness to execute arbitrary SQL commands that could lead to unauthorized data access or manipulation, compromising the integrity and confidentiality of the system's database. Protecting against such vulnerabilities is critical for the security of web applications, and it is advised to validate and sanitize user inputs effectively.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database0 Proof of Concept(s)
.