{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-5300","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-09-29T16:01:21.926Z","datePublished":"2023-09-30T10:00:05.991Z","dateUpdated":"2024-08-02T07:52:08.546Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-10-25T04:58:10.913Z"},"title":"TTSPlanning sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"n/a","product":"TTSPlanning","versions":[{"version":"20230925","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability classified as critical has been found in TTSPlanning up to 20230925. This affects an unknown part. The manipulation of the argument uid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240939."},{"lang":"de","value":"Es wurde eine Schwachstelle in TTSPlanning bis 20230925 entdeckt. Sie wurde als kritisch eingestuft. Betroffen hiervon ist ein unbekannter Ablauf. Mittels Manipulieren des Arguments uid mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2023-09-29T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-09-29T00:00:00.000Z","lang":"en","value":"CVE reserved"},{"time":"2023-09-29T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-10-22T15:54:10.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"CV3TR4CK (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.240939","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.240939","tags":["signature","permissions-required"]},{"url":"https://github.com/CV3TR4CK/CV3Cyb3R/blob/main/2023/TTSPlanning/TTSPlanning.md","tags":["exploit"]}]},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2023-5300","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-05-15T19:30:22.939779Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:28:33.323Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T07:52:08.546Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.240939","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.240939","tags":["signature","permissions-required","x_transferred"]},{"url":"https://github.com/CV3TR4CK/CV3Cyb3R/blob/main/2023/TTSPlanning/TTSPlanning.md","tags":["exploit","x_transferred"]}]}]}}