whoissecure/Simple-Subscription-Website-Exploits

whoissecure/Simple-Subscription-Website-Exploits

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases0
Exploits in Simple Subscription Company to dump users and hashes from database.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

9.8 CRITICAL7.5 HIGH

Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.