ally-petitt/CVE-2023-45503

ally-petitt/CVE-2023-45503

Releases0
Stars1
CVE-2023-45503 Reference

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.