CVE-2023-1848
published 2023-04-05CVE-2023-1848: A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been classified as critical. Affected is an unknown function of the file…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.81%
52.7th percentile
A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/attendance_row.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224988.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| online_payroll_system_project | online_payroll_system | — | — |
| sourcecodester | online_payroll_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h5p8-crm6-4r5v: A vulnerability was found in SourceCodester Online Payroll System 1
ghsa_unreviewed·2023-04-05
CVE-2023-1848 [CRITICAL] CWE-89 GHSA-h5p8-crm6-4r5v: A vulnerability was found in SourceCodester Online Payroll System 1
A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/attendance_row.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224988.
Red Hat
vim: heap-buffer-overflow in vim_regsub_both in vim/vim
vendor_redhat·2023-09-02·CVSS 7.8
CVE-2023-4738 [HIGH] CWE-122 vim: heap-buffer-overflow in vim_regsub_both in vim/vim
vim: heap-buffer-overflow in vim_regsub_both in vim/vim
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
Statement: Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.
For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/
Package: vim (Red Hat Enterprise Linux 8) - Fix deferred
Package: vim (Red Hat Enterprise Linux 9) - Fix deferred
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/E1CHO/cve_hub/blob/main/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide%20-%20vlun%203.pdfhttps://vuldb.com/?ctiid.224988https://vuldb.com/?id.224988https://github.com/E1CHO/cve_hub/blob/main/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide%20-%20vlun%203.pdfhttps://vuldb.com/?ctiid.224988https://vuldb.com/?id.224988
2023-04-05
Published