CVE-2023-43013
CRITICALAsset Management System v1.0 - Unauthenticated SQL Injection
Title source: llmDescription
Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://fluidattacks.com/advisories/nergal
Product
https://projectworlds.in/
Scores
CVSS v3
9.8
EPSS
0.0004
EPSS Percentile
11.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
projectworlds/asset_management_system
1.0
Published
Sep 28, 2023
Tracked Since
Feb 18, 2026