SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://docs.google.com/spreadsheets/d/1AzXspN8oBAJ80YQxfN44bpbOuNzA3PZEccQ6IGQMs5E/edit?usp=sharing | Not Applicable |
https://docs.google.com/spreadsheets/d/1AzXspN8oBAJ80YQxfN44bpbOuNzA3PZEccQ6IGQMs5E/edit?usp=sharing | Not Applicable |
https://github.com/ally-petitt/CVE-2023-45503?tab=readme-ov-file | Exploit Third Party Advisory |
https://github.com/ally-petitt/CVE-2023-45503?tab=readme-ov-file | Exploit Third Party Advisory |
Configurations
History
18 Apr 2025, 18:34
Type | Values Removed | Values Added |
---|---|---|
First Time |
Macs Cms Project
Macs Cms Project macs Cms |
|
CPE | cpe:2.3:a:macs_cms_project:macs_cms:1.1.4f:*:*:*:*:*:*:* | |
References | () https://github.com/ally-petitt/CVE-2023-45503?tab=readme-ov-file - Exploit, Third Party Advisory | |
References | () https://docs.google.com/spreadsheets/d/1AzXspN8oBAJ80YQxfN44bpbOuNzA3PZEccQ6IGQMs5E/edit?usp=sharing - Not Applicable |
16 Apr 2024, 13:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-15 20:15
Updated : 2025-04-18 18:34
NVD link : CVE-2023-45503
Mitre link : CVE-2023-45503
JSON object : View
Products Affected
macs_cms_project
- macs_cms
CWE
No CWE.