CVE-2023-31714
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
- Published
- Aug 30, 2023
- Updated
- Oct 1, 2024
- Assigning CNA
- mitre
- Evidence observed
- Apr 20, 2023
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
Proof-of-concept exploit for CVE-2023-31714, a pre-authentication SQL injection in Chitor-CMS < 1.1.2. Automates database enumeration and credential dumping via the /edit_school.php endpoint.
msd0pe · php · Apr 20, 2023
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.