CVE-2023-44267

CRITICAL

Online Art Gallery 1.0 - Unauthenticated SQL Injection via lnm Parameter

Title source: llm
STIX 2.1

Description

Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://fluidattacks.com/advisories/ono

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
projectworlds/online_art_gallery 1.0
Published Oct 26, 2023
Tracked Since Feb 18, 2026