Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2023-46024

CWE-89SQL Injection4 documents4 sources
Severity
7.5HIGH
EPSS
2.4%
top 14.87%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 14
Latest updateMar 20

Description

SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-jmvp-x9cx-79mx: SQL Injection vulnerability in index2023-11-15
CVEList
CVE-2023-46024: SQL Injection vulnerability in index2023-11-14

💥Exploits & PoCs

1
Exploit-DB
Teacher Subject Allocation Management System 1.0 - 'searchdata' SQLi2024-03-20
CVE-2023-46024 (HIGH CVSS 7.5) | SQL Injection vulnerability in inde | cvebase.io