CVE-2023-2151
published 2023-04-18CVE-2023-2151: A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.77%
51.2th percentile
A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_edge | — | — |
| msrc | microsoft_edge_extended_stable | — | — |
| msrc | microsoft_edge_for_android | — | — |
| oretnom23 | student_study_center_desk_management_system | — | — |
| sourcecodester | student_study_center_desk_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3ghf-mqfr-9xvw: A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1
ghsa_unreviewed·2023-04-18
CVE-2023-2151 [MEDIUM] CWE-89 GHSA-3ghf-mqfr-9xvw: A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1
A vulnerability, which was classified as critical, was found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226272.
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2023-11-14·CVSS 6.6
CVE-2023-36008 [MEDIUM] CWE-416 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
119.0.2151.72
11/16/2023
119.0.6045.159/.160
Extended Stable
118.0.2088.109
11/16/2023
118.0.5993.144
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally.
For example, when the score indicates that the Attack Vector is Local and User Interaction is Required, this could describe an exploit in whi
Microsoft
Chromium: CVE-2023-5850 Incorrect security UI in Downloads
vendor_msrc·2023-11-14·CVSS 4.3
CVE-2023-5850 [MEDIUM] Chromium: CVE-2023-5850 Incorrect security UI in Downloads
Chromium: CVE-2023-5850 Incorrect security UI in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the
Microsoft
Chromium: CVE-2023-5849 Integer overflow in USB
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5849 [HIGH] Chromium: CVE-2023-5849 Integer overflow in USB
Chromium: CVE-2023-5849 Integer overflow in USB
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2023-5853 Incorrect security UI in Downloads
vendor_msrc·2023-11-14·CVSS 4.3
CVE-2023-5853 [MEDIUM] Chromium: CVE-2023-5853 Incorrect security UI in Downloads
Chromium: CVE-2023-5853 Incorrect security UI in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the
Microsoft
Chromium: CVE-2023-5480 Inappropriate implementation in Payments
vendor_msrc·2023-11-14·CVSS 6.1
CVE-2023-5480 [MEDIUM] Chromium: CVE-2023-5480 Inappropriate implementation in Payments
Chromium: CVE-2023-5480 Inappropriate implementation in Payments
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version
Microsoft
Chromium: CVE-2023-5858 Inappropriate implementation in WebApp Provider
vendor_msrc·2023-11-14·CVSS 4.3
CVE-2023-5858 [MEDIUM] Chromium: CVE-2023-5858 Inappropriate implementation in WebApp Provider
Chromium: CVE-2023-5858 Inappropriate implementation in WebApp Provider
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the v
Microsoft
Chromium: CVE-2023-5852 Use after free in Printing
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5852 [HIGH] Chromium: CVE-2023-5852 Use after free in Printing
Chromium: CVE-2023-5852 Use after free in Printing
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser
Microsoft
Chromium: CVE-2023-5859 Incorrect security UI in Picture In Picture
vendor_msrc·2023-11-14·CVSS 4.3
CVE-2023-5859 [MEDIUM] Chromium: CVE-2023-5859 Incorrect security UI in Picture In Picture
Chromium: CVE-2023-5859 Incorrect security UI in Picture In Picture
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the versi
Microsoft
Chromium: CVE-2023-5996 Use after free in WebAudio
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5996 [HIGH] Chromium: CVE-2023-5996 Use after free in WebAudio
Chromium: CVE-2023-5996 Use after free in WebAudio
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
119.0.2151.58
11/09/2023
119.0.6045.123/.124
Extended Stable
118.0.2088.102
11/09/2023
118.0.5993.136
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsof
Microsoft
Microsoft Edge (Chromium-based) Spoofing Vulnerability
vendor_msrc·2023-11-14·CVSS 4.3
CVE-2023-36029 [MEDIUM] Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
119.0.2151.44
11/02/2023
119.0.6045.105/.106
Extended Stable
118.0.2088.88
11/02/2023
118.0.5993.
Microsoft
Chromium: CVE-2023-5855 Use after free in Reading Mode
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5855 [HIGH] Chromium: CVE-2023-5855 Use after free in Reading Mode
Chromium: CVE-2023-5855 Use after free in Reading Mode
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the bro
Microsoft
Chromium: CVE-2023-5857 Inappropriate implementation in Downloads
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5857 [HIGH] Chromium: CVE-2023-5857 Inappropriate implementation in Downloads
Chromium: CVE-2023-5857 Inappropriate implementation in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version
Microsoft
Chromium: CVE-2023-5854 Use after free in Profiles
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5854 [HIGH] Chromium: CVE-2023-5854 Use after free in Profiles
Chromium: CVE-2023-5854 Use after free in Profiles
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser
Microsoft
Chromium: CVE-2023-5851 Inappropriate implementation in Downloads
vendor_msrc·2023-11-14·CVSS 4.3
CVE-2023-5851 [MEDIUM] Chromium: CVE-2023-5851 Inappropriate implementation in Downloads
Chromium: CVE-2023-5851 Inappropriate implementation in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version
Microsoft
Chromium: CVE-2023-5482 Insufficient data validation in USB
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5482 [HIGH] Chromium: CVE-2023-5482 Insufficient data validation in USB
Chromium: CVE-2023-5482 Insufficient data validation in USB
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of th
Microsoft
Chromium: CVE-2023-5856 Use after free in Side Panel
vendor_msrc·2023-11-14·CVSS 8.8
CVE-2023-5856 [HIGH] Chromium: CVE-2023-5856 Use after free in Side Panel
Chromium: CVE-2023-5856 Use after free in Side Panel
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
119.0.2151.44
11/02/2023
119.0.6045.105/.106
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the brows
Red Hat
pcs: webpack: Regression of CVE-2023-28154 fixes in the Red Hat Enterprise Linux
vendor_redhat·2023-05-09·CVSS 9.8
CVE-2023-2319 [CRITICAL] pcs: webpack: Regression of CVE-2023-28154 fixes in the Red Hat Enterprise Linux
pcs: webpack: Regression of CVE-2023-28154 fixes in the Red Hat Enterprise Linux
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linux 9.2.
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-18
Published