CVE-2023-2149 is a critical SQL injection vulnerability in Campcodes Online Thesis Archiving System 1.0, specifically within the /admin/user/manage_user.php file. An unauthenticated attacker can remotely exploit this flaw by manipulating the 'id' argument, leading to full compromise of the system. With a CVSS score of 9.8, this vulnerability allows for complete confidentiality, integrity, and availability impact. While public exploit details exist, there is no evidence of active exploitation in the wild, nor are there readily available Metasploit or Nuclei modules. Despite limited community discussion, the public disclosure of the exploit code indicates a heightened risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:online_thesis_archiving_system_project:online_thesis_archiving_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.