VDB
CVE-2023-4845
CVE-2023-4845
PUBLISHED
CVSS 6.300000190734863 MEDIUM
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file account_edit_query.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239254 is the identifier assigned to this vulnerability.
EPSS 0.05% · 14.9th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.05%
14.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| razormist | simple_membership_system | 1.0, 1.0 |
| SourceCodester | Simple Membership System | 1.0, 1.0 |
Exploit Intelligence
Timeline
- Sep 9, 2023 EPSS Score
- Sep 9, 2023 CVE Published
- Sep 9, 2023 PoC Published
- Oct 12, 2023 EPSS Score
- Nov 13, 2023 EPSS Score
- Dec 16, 2023 EPSS Score
- Jan 17, 2024 EPSS Score
- Feb 19, 2024 EPSS Score
- Mar 22, 2024 EPSS Score
- Apr 24, 2024 EPSS Score
- May 26, 2024 EPSS Score
- Jun 28, 2024 EPSS Score