CVE-2023-5020
Published on: Not Yet Published
Last Modified on: 09/20/2023 03:42:00 PM UTC
Certain versions of Customer Relationship Management from 07fly contain the following vulnerability:
A vulnerability, which was classified as critical, has been found in 07FLY CRM V2. This issue affects some unknown processing of the file /index.php/sysmanage/Login/login_auth/ of the component Administrator Login Page. The manipulation of the argument account leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239861 was assigned to this vulnerability.
- CVE-2023-5020 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
07FLY - CRM version = V2
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Login required | vuldb.com text/html Inactive LinkNot Archived |
![]() |
CVE-2023-5020: 07FLY CRM Administrator Login Page sql injection | vuldb.com text/html |
![]() |
GitHub - chosir/exp | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | 07fly | Customer Relationship Management | 2.0 | All | All | All |
- cpe:2.3:a:07fly:customer_relationship_management:2.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE