github.com
https://github.com/zPrototype/CVE-2023-29809 CVE-2023-29809
CRITICAL
Cmaps v8.0 - SQL injection
Record summary
CVE-2023-29809 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBCmaps v8.0 - SQL injectionExploitDB exploitby Lucas Noki (0xPrototype)Not analyzed1 file
Repository PoCs
GitHubzPrototype/CVE-2023-29809Repository PoCby zPrototypeStars: 1Not analyzed3 files
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-29809 packetstormsecurity.com
https://packetstormsecurity.com/files/172146/Companymaps-8.0-SQL-Injection.html exploit-db.com
https://www.exploit-db.com/exploits/51422