CVE-2023-1464
published 2023-03-17CVE-2023-1464: A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.79%
52.1th percentile
A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file Users.php?f=save_user. The manipulation of the argument firstname/middlename/lastname/username/password leads to improper authentication. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-223311.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| medicine_tracker_system_project | medicine_tracker_system | — | — |
| sourcecodester | medicine_tracker_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
cisa5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8283-337p-pfcj: A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1
ghsa_unreviewed·2023-03-17
CVE-2023-1464 [CRITICAL] CWE-287 GHSA-8283-337p-pfcj: A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1
A vulnerability, which was classified as critical, was found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file Users.php?f=save_user. The manipulation of the argument firstname/middlename/lastname/username/password leads to improper authentication. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-223311.
CISA
Cisco IOS Denial-of-Service Vulnerability
cisa·2023-05-19·CVSS 5.9
CVE-2004-1464 [MEDIUM] Cisco IOS Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Denial-of-Service Vulnerability
Affected: Cisco IOS
Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.
Required Action: Apply updates per vendor instructions.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20040827-telnet; https://nvd.nist.gov/vuln/detail/CVE-2004-1464
Remediation Due Date: 2023-06-09
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-17
Published