Rail Pass MS v1.0 Remote SQLi via editid in edit-pass-detail.php
CVE-2023-31933 Published on July 28, 2023
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file.
Products Associated with CVE-2023-31933
stack.watch emails you whenever new vulnerabilities are published in Railpassmanagementsystemproject Rail Pass Management System or PHPGurukul Rail Pass Management System. Just hit a watch button to start following.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.