logo

CVE-2023-47438 reportico-web/reportico

Package

Manager: composer
Name: reportico-web/reportico
Vulnerable Version: >=0 <=8.1.0

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00123 pctl0.32128

Details

SQL Injection vulnerability in Reportico Till SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system information via the project parameter.

Metadata

Created: 2024-03-28T00:31:37Z
Modified: 2024-11-18T16:26:38Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-jjf4-959w-f545/GHSA-jjf4-959w-f545.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-jjf4-959w-f545
Finding: F297
Auto approve: 1