CVE-2023-4407 is a critical SQL injection vulnerability affecting Codecanyon Credit Lite version 1.5.4. Specifically, it impacts the /portal/reports/account_statement functionality when handling POST requests, allowing manipulation of the date1/date2 arguments. With a CVSS score of 9.8, this vulnerability is easily exploitable remotely with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not currently in the KEV catalog or showing significant community discussion, a public exploit (EDB-51701) exists, indicating a potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.4CPE matchmatch criteria | cpe:2.3:a:credit_lite_project:credit_lite:1.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.