Shanghai CTI Navigation CTI Monitoring and Early Warning System UserEdit.aspx sql injection
CVE-2023-5827
Key Information:
- Vendor
Shanghai Cti Navigation
- Vendor
- CVE Published:
- 27 October 2023
Badges
What is CVE-2023-5827?
A security vulnerability in the Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2 allows for SQL injection through manipulation of the ID argument in the UserEdit.aspx file. This could potentially enable attackers to execute arbitrary SQL commands, compromising the integrity of the database. Given that this vulnerability has been publicly disclosed, systems utilizing this software should take immediate action to mitigate potential exploitation.
Affected Version(s)
CTI Monitoring and Early Warning System 2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
