Lucene search

K
cveMitreCVE-2023-50071
HistoryDec 29, 2023 - 10:15 p.m.

CVE-2023-50071

2023-12-2922:15:37
CWE-89
mitre
web.nvd.nist.gov
20
cve-2023-50071
sourcecodester
customer support system
sql injection
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

22.8%

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.

Affected configurations

Nvd
Node
customer_support_system_projectcustomer_support_systemMatch1.0
VendorProductVersionCPE
customer_support_system_projectcustomer_support_system1.0cpe:2.3:a:customer_support_system_project:customer_support_system:1.0:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

22.8%