CVE-2023-5033
Published on: Not Yet Published
Last Modified on: 09/19/2023 01:15:00 PM UTC
Certain versions of Rapidcms from Openrapid contain the following vulnerability:
A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /admin/category/cate-edit-run.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239877 was assigned to this vulnerability.
- CVE-2023-5033 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
OpenRapid - RapidCMS version = 1.3.1
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
SQL injection vulnerability exists in RapidCMS Dev.1.3.1 --2 · Issue #3 · yhy217/rapidcms-vul · GitHub | github.com text/html |
![]() |
Login required | vuldb.com text/html Inactive LinkNot Archived |
![]() |
CVE-2023-5033: OpenRapid RapidCMS cate-edit-run.php sql injection | vuldb.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Openrapid | Rapidcms | 1.3.1 | All | All | All |
- cpe:2.3:a:openrapid:rapidcms:1.3.1:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE