CVE-2023-45503

MEDIUM

Macs Cms - SQL Injection

Title source: rule
STIX 2.1

Description

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.

Exploits (1)

nomisec WRITEUP
by ally-petitt · poc
https://github.com/ally-petitt/CVE-2023-45503

Scores

CVSS v3 5.3
EPSS 0.0184
EPSS Percentile 83.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
macs_cms_project/macs_cms 1.1.4f
Published Apr 15, 2024
Tracked Since Feb 18, 2026