CVE-2023-48078

CRITICAL

Simple CRUD Functionality 1.0 - SQL Injection via Title Parameter

Title source: llm
STIX 2.1

Description

SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.

Scores

CVSS v3 9.8
EPSS 0.0010
EPSS Percentile 26.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
code-projects/simple_crud_functionality 1.0
Published Nov 17, 2023
Tracked Since Feb 18, 2026