📦

asset_management_system

Vendor: projectworlds

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.68% Exploit Prob.
Latest CVE CVE-2023-43014 Sep 28

Security Vulnerability Index

Page 1 / 1
8.8 CVSS

Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.

EPSS: 0.65%
9.8 CVSS

Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

EPSS: 0.71%