CVE-2023-53917
MEDIUMAffiliate Me <5.0.1 - SQL Injection
Title source: llmDescription
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.0004
EPSS Percentile
13.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-89
Status
published
Products (2)
powerstonegh/Affiliate Me
5.0.1
powerstonegh/affiliate_me
5.0.1
Published
Dec 17, 2025
Tracked Since
Feb 18, 2026