CVE-2023-47438 – reportico-web/reportico
Package
Manager: composer
Name: reportico-web/reportico
Vulnerable Version: >=0 <=8.1.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00123 pctl0.32128
Details
SQL Injection vulnerability in Reportico Till SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system information via the project parameter.
Metadata
Created: 2024-03-28T00:31:37Z
Modified: 2024-11-18T16:26:38Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-jjf4-959w-f545/GHSA-jjf4-959w-f545.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-jjf4-959w-f545
Finding: F297
Auto approve: 1