CVE-2023-43144

CRITICAL

Assets-management-system-in-php 1.0 - SQL Injection

Title source: llm

Description

Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.

Exploits (1)

nomisec WORKING POC
by Pegasus0xx · poc
https://github.com/Pegasus0xx/CVE-2023-43144

Scores

CVSS v3 9.8
EPSS 0.0278
EPSS Percentile 86.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
projectworlds/asset_management_system_project_in_php 1.0
Published Sep 22, 2023
Tracked Since Feb 18, 2026