CVE-2023-31753

CRITICAL

eNdonesia 8.7 - SQL Injection via diskusi.php rid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-31753. PoCs published by KIL0BYT3X.

AI-analyzed exploit summary This PoC demonstrates a SQL injection vulnerability in eNdonesia Portal v8.7 via the 'rid' parameter in diskusi.php, using a time-based payload to confirm exploitation.

Description

SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.

Exploits (2)

nomisec WORKING POC
by KIL0BYT3X · poc
https://github.com/KIL0BYT3X/CVE-2023-31753

This PoC demonstrates a SQL injection vulnerability in eNdonesia Portal v8.7 via the 'rid' parameter in diskusi.php, using a time-based payload to confirm exploitation.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: eNdonesia Portal 8.7
No auth needed
Prerequisites: Access to the vulnerable endpoint · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/khmk2k/cve-2023-31753

This repository contains a functional proof-of-concept for CVE-2023-31753, demonstrating a SQL injection vulnerability in eNdonesia Portal v8.7 via the 'rid' parameter in diskusi.php. The PoC includes a crafted HTTP request with a sleep payload to confirm the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: eNdonesia Portal v8.7
No auth needed
Prerequisites: Access to the vulnerable endpoint · Ability to send HTTP requests
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Patch, Product, Third Party Advisory
https://github.com/khmk2k/CVE-2023-31753/

Scores

CVSS v3 9.8
EPSS 0.0372
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
endonesia/endonesia 8.7
Published Jul 20, 2023
Tracked Since Feb 18, 2026