CVE-2023-31753

SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.
References
Link Resource
https://github.com/khmk2k/CVE-2023-31753/ Exploit Patch Product Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:endonesia:endonesia:8.7:*:*:*:*:*:*:*

History

27 Jul 2023, 23:37

Type Values Removed Values Added
References (MISC) https://github.com/khmk2k/CVE-2023-31753/ - (MISC) https://github.com/khmk2k/CVE-2023-31753/ - Exploit, Patch, Product, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:endonesia:endonesia:8.7:*:*:*:*:*:*:*
CWE CWE-89
First Time Endonesia endonesia
Endonesia

20 Jul 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-20 20:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-31753

Mitre link : CVE-2023-31753

CVE.ORG link : CVE-2023-31753


JSON object : View

Products Affected

endonesia

  • endonesia
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')