Headline
CVE-2023-43014: Asset Management System v1.0 - Authenticated SQL Injection (SQLi) | Advisories | Fluid Attacks
Asset Management System v1.0 is vulnerable to
an Authenticated SQL Injection vulnerability
on the ‘first_name’ and ‘last_name’ parameters
of user.php page, allowing an authenticated
attacker to dump all the contents of the database
contents.
Hacking software for over 20 years
Fluid Attacks tests applications and other systems, covering all software development stages. Our team assists clients in quickly identifying and managing vulnerabilities to reduce the risk of incidents and deploy secure technology.