NA

CVE-2023-45503

Published: 15/04/2024 Updated: 16/04/2024

Vulnerability Summary

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote malicious users to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.

Github Repositories

CVE-2023-45503 Reference

CVE-2023-45503 Vulnerability Details Overview In Macrob7 Macs Framework Content Management System (CMS) versions 114f and prior, insecure handling of user input leads to 16 SQL injection vulnerabilities The ability to execute arbitrary SQL queries can lead to private data being leaked including users' password hashes and the ability to modify other users' credentia