Lucene search

K
cveVulDBCVE-2023-0641
HistoryFeb 02, 2023 - 9:15 a.m.

CVE-2023-0641

2023-02-0209:15:08
CWE-521
VulDB
web.nvd.nist.gov
60
cve-2023-0641
phpgurukul
employee leaves management system
vulnerability
weak password
changepassword.php
remote attack
vdb-220021
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

49.4%

A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to weak password requirements. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-220021 was assigned to this vulnerability.

Affected configurations

Nvd
Vulners
Node
employee_leaves_management_system_projectemployee_leaves_management_systemMatch1.0
VendorProductVersionCPE
employee_leaves_management_system_projectemployee_leaves_management_system1.0cpe:2.3:a:employee_leaves_management_system_project:employee_leaves_management_system:1.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "PHPGurukul",
    "product": "Employee Leaves Management System",
    "versions": [
      {
        "version": "1.0",
        "status": "affected"
      }
    ]
  }
]

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

49.4%

Related for CVE-2023-0641