Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-27742. PoCs published by G37SYS73M.
AI-analyzed exploit summary The repository describes a SQL injection vulnerability in IDURAR ERP/CRM v1 via the /api/login endpoint, where the attack vector involves using the expression {"$ne":null} in the email keypair. However, it lacks functional exploit code or detailed technical analysis.
Description
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
Exploits (1)
The repository describes a SQL injection vulnerability in IDURAR ERP/CRM v1 via the /api/login endpoint, where the attack vector involves using the expression {"$ne":null} in the email keypair. However, it lacks functional exploit code or detailed technical analysis.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H