VDB
CVE-2023-4846
CVE-2023-4846
PUBLISHED
CVSS 6.300000190734863 MEDIUM
A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been rated as critical. This issue affects some unknown processing of the file delete_member.php. The manipulation of the argument mem_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239255.
EPSS 0.05% · 16.6th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.05%
16.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| razormist | simple_membership_system | 1.0, 1.0 |
| SourceCodester | Simple Membership System | 1.0, 1.0 |
Exploit Intelligence
- CIRCL seen: CVE-2023-4846 (circl-sighting)
- CIRCL published-proof-of-concept: CVE-2023-4846 (circl-sighting)
- https://vuldb.com/?id.239255 (circl)
- https://vuldb.com/?ctiid.239255 (circl)
- https://github.com/Swpan2018/Vulhub/blob/main/Simple-Membership-System%20delete_member.php%20has%20Sqlinjection.pdf (cve.org)
Timeline
- Sep 9, 2023 EPSS Score
- Sep 9, 2023 CVE Published
- Sep 10, 2023 PoC Published
- Oct 12, 2023 EPSS Score
- Nov 13, 2023 EPSS Score
- Dec 16, 2023 EPSS Score
- Jan 17, 2024 EPSS Score
- Feb 19, 2024 EPSS Score
- Mar 22, 2024 EPSS Score
- Apr 24, 2024 EPSS Score
- May 26, 2024 EPSS Score
- Jun 28, 2024 EPSS Score