github.com
https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/ANUJ-KUMAR/Old-Age-Home-Management-2022-2023-1.0 CVE-2023-33338
CRITICALNuclei
Old Age Home Management System v1.0 - SQL Injection
Record summary
CVE-2023-33338 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALOld Age Home Management System v1.0 - SQL InjectionCVSS 9.8
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest patches or updates provided by the vendor to fix the SQL Injection vulnerability in the Old Age Home Management System v1.0.
WeaknessesCWE-89
AuthorsHarsh
Template tagscve2023cveoahmssqliauth-bypassphpgurukulvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:phpgurukul:old_age_home_management_system:1.0:*:*:*:*:*:*:*
https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/ANUJ-KUMAR/Old-Age-Home-Management-2022-2023-1.0 https://nvd.nist.gov/vuln/detail/CVE-2023-33338
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-33338