Lucene search

K
cveMitreCVE-2023-29626
HistoryApr 14, 2023 - 2:15 a.m.

CVE-2023-29626

2023-04-1402:15:13
CWE-89
mitre
web.nvd.nist.gov
73
cve-2023-29626
yoga class registration system
sql injection
admin login page

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

50.1%

Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php.

Affected configurations

Nvd
Node
yoga_class_registration_system_projectyoga_class_registration_systemMatch1.0
VendorProductVersionCPE
yoga_class_registration_system_projectyoga_class_registration_system1.0cpe:2.3:a:yoga_class_registration_system_project:yoga_class_registration_system:1.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

50.1%

Related for CVE-2023-29626