Record summary

CVE-2023-33338 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALOld Age Home Management System v1.0 - SQL InjectionCVSS 9.8

Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Apply the latest patches or updates provided by the vendor to fix the SQL Injection vulnerability in the Old Age Home Management System v1.0.

WeaknessesCWE-89
AuthorsHarsh
Template tagscve2023cveoahmssqliauth-bypassphpgurukulvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:phpgurukul:old_age_home_management_system:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2