CVE-2023-36076
PoC —CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
Modified
Description
SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.
- Vendors
- pocketmanga
- Products
- smanga
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.