Record summary

CVE-2023-29809 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 24, 2025 · Source: CVE List

Proofs of concept

2

Catalogued exploits

ExploitDBCmaps v8.0 - SQL injectionExploitDB exploitby Lucas Noki (0xPrototype)Not analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubzPrototype/CVE-2023-29809Repository PoCby zPrototypeStars: 1Not analyzed3 files

343.3 KiB

GitHub

PoC details

References

4