{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-5471","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2023-10-09T18:48:15.490Z","datePublished":"2023-10-10T01:00:07.923Z","dateUpdated":"2024-09-19T14:02:48.399Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-10-10T01:00:07.923Z"},"title":"codeprojects Farmacia index.php sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"codeprojects","product":"Farmacia","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as critical, was found in codeprojects Farmacia 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument usario/senha leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241608."},{"lang":"de","value":"Es wurde eine Schwachstelle in codeprojects Farmacia 1.0 gefunden. Sie wurde als kritisch eingestuft. Dabei betrifft es einen unbekannter Codeteil der Datei index.php. Durch Manipulation des Arguments usario/senha mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2023-10-09T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2023-10-09T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-10-09T20:54:59.000Z","lang":"en","value":"VulDB last update"}],"credits":[{"lang":"en","value":"miziha (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.241608","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.241608","tags":["signature","permissions-required"]},{"url":"https://github.com/miziha6/cve/blob/main/Farmacia%20System.pdf","tags":["exploit"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T07:59:44.690Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.241608","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.241608","tags":["signature","permissions-required","x_transferred"]},{"url":"https://github.com/miziha6/cve/blob/main/Farmacia%20System.pdf","tags":["exploit","x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-19T14:02:38.260582Z","id":"CVE-2023-5471","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-19T14:02:48.399Z"}}]}}