gopeak MasterLab har 3.3.10 HTTP POST Request Feature.php sqlInject pwd SQL Injection
Wuro vulnerability wey an yi classify sey kura an gano shi a cikin gopeak MasterLab har 3.3.10. Gaskiya, sqlInject na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, app/ctrl/framework/Feature.php na cikin fayil, HTTP POST Request Handler na cikin sashi. Ngam manipulation of the argument pwd shi SQL Injection. CWE shidin ka a yi bayani matsala sai ya kai CWE-89. Gaskiya, laifi an fitar da shi 12/28/2023. Advisory ɗin ana rabawa don saukewa a note.zhaoj.in. Wannan rauni ana sayar da shi da suna CVE-2023-7144. Wuro ndiyam na local network ɗin sai a samu kafin wannan hari ya yi nasara. Tekinikal bayani ga. Kuma, exploit ɗin yana akwai. Wuro exploit ɗin an bayyana shi ga jama'a kuma za a iya amfani da shi. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á wúro huɗɗi-na-gaskiya. Wona yiwuwa a zazzage exploit a note.zhaoj.in. Kama 0-day, an ndiyam a wuro be $0-$5k. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.
2 Goyarwa · 73 Datenpunkte
| Furɗe | Súgá 12/28/2023 09:38 | Gargadi 1/1 01/20/2024 09:23 |
|---|---|---|
| software_vendor | gopeak | gopeak |
| software_name | MasterLab | MasterLab |
| software_version | <=3.3.10 | <=3.3.10 |
| software_component | HTTP POST Request Handler | HTTP POST Request Handler |
| software_file | app/ctrl/framework/Feature.php | app/ctrl/framework/Feature.php |
| software_function | sqlInject | sqlInject |
| software_argument | pwd | pwd |
| vulnerability_cwe | CWE-89 (SQL Injection) | CWE-89 (SQL Injection) |
| vulnerability_risk | 2 | 2 |
| cvss3_vuldb_ac | L | L |
| cvss3_vuldb_pr | N | N |
| cvss3_vuldb_ui | N | N |
| cvss3_vuldb_s | U | U |
| cvss3_vuldb_c | L | L |
| cvss3_vuldb_i | L | L |
| cvss3_vuldb_a | L | L |
| cvss3_vuldb_e | P | P |
| cvss3_vuldb_rc | R | R |
| advisory_url | https://note.zhaoj.in/share/4HDWrBHGCf9e | https://note.zhaoj.in/share/4HDWrBHGCf9e |
| exploit_availability | 1 | 1 |
| exploit_publicity | 1 | 1 |
| exploit_url | https://note.zhaoj.in/share/4HDWrBHGCf9e | https://note.zhaoj.in/share/4HDWrBHGCf9e |
| source_cve | CVE-2023-7144 | CVE-2023-7144 |
| cna_responsible | VulDB | VulDB |
| advisory_date | 1703718000 (12/28/2023) | 1703718000 (12/28/2023) |
| cvss2_vuldb_ac | L | L |
| cvss2_vuldb_au | N | N |
| cvss2_vuldb_ci | P | P |
| cvss2_vuldb_ii | P | P |
| cvss2_vuldb_ai | P | P |
| cvss2_vuldb_e | POC | POC |
| cvss2_vuldb_rc | UR | UR |
| cvss2_vuldb_av | A | A |
| cvss2_vuldb_rl | ND | ND |
| cvss3_vuldb_av | A | A |
| cvss3_vuldb_rl | X | X |
| cvss2_vuldb_basescore | 5.8 | 5.8 |
| cvss2_vuldb_tempscore | 5.0 | 5.0 |
| cvss3_vuldb_basescore | 6.3 | 6.3 |
| cvss3_vuldb_tempscore | 5.7 | 5.7 |
| cvss3_meta_basescore | 6.3 | 7.5 |
| cvss3_meta_tempscore | 5.7 | 7.3 |
| price_0day | $0-$5k | $0-$5k |
| cve_assigned | 1703718000 (12/28/2023) | |
| cve_nvd_summary | A vulnerability classified as critical has been found in gopeak MasterLab up to 3.3.10. This affects the function sqlInject of the file app/ctrl/framework/Feature.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249147. | |
| cvss3_cna_pr | N | |
| cvss3_cna_ui | N | |
| cvss3_cna_s | U | |
| cvss3_cna_c | L | |
| cvss3_cna_i | L | |
| cvss3_cna_a | L | |
| cve_cna | VulDB | |
| cvss2_nvd_basescore | 5.8 | |
| cvss3_nvd_basescore | 9.8 | |
| cvss3_cna_basescore | 6.3 | |
| cvss3_nvd_av | N | |
| cvss3_nvd_ac | L | |
| cvss3_nvd_pr | N | |
| cvss3_nvd_ui | N | |
| cvss3_nvd_s | U | |
| cvss3_nvd_c | H | |
| cvss3_nvd_i | H | |
| cvss3_nvd_a | H | |
| cvss2_nvd_av | A | |
| cvss2_nvd_ac | L | |
| cvss2_nvd_au | N | |
| cvss2_nvd_ci | P | |
| cvss2_nvd_ii | P | |
| cvss2_nvd_ai | P | |
| cvss3_cna_av | A | |
| cvss3_cna_ac | L |