SQL Injection Vulnerability in Packers and Movers Management System by Geilihan
CVE-2023-46956

7.2HIGH

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
30 November 2023

What is CVE-2023-46956?

The Packers and Movers Management System v1.0 contains an SQL injection vulnerability that permits remote attackers to execute arbitrary code. By manipulating the 'id' parameter in a request to the user management file located at /mpms/admin/?page=user/manage_user&id, an attacker can craft malicious payloads that compromise the security of the application and potentially gain unauthorized access to sensitive data or perform unauthorized actions.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.