ZeroHour

CVE-2023-36076

PoC
CVSS 3.1
9.8 critical
EPSS
3%p86
Published
()
Modified
Description

SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.

Vendors
pocketmanga
Products
smanga
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.