Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-98207
HistoryOct 30, 2023 - 12:00 a.m.

Simple Real Estate Portal System SQL Injection Vulnerability (CNVD-2023-98207)

2023-10-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
4
real estate portal system
sql injection
vulnerability
validation
illegal commands
database theft

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

27.3%

Simple Real Estate Portal System is a real estate portal system. A SQL injection vulnerability exists in Simple Real Estate Portal System v1.0, which originates from the parameter id of the file view_estate.php that lacks validation of externally entered SQL statements. An attacker can exploit this vulnerability to execute illegal SQL commands to steal sensitive database data.

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

27.3%

Related for CNVD-2023-98207