{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-04T05:46:27.552","vulnerabilities":[{"cve":{"id":"CVE-2023-43013","sourceIdentifier":"help@fluidattacks.com","published":"2023-09-28T21:15:10.037","lastModified":"2026-06-17T06:24:59.197","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Asset Management System v1.0 is vulnerable to an\n\nunauthenticated SQL Injection vulnerability on the\n\n'email' parameter of index.php page, allowing an\n\nexternal attacker to dump all the contents of the\n\ndatabase contents and bypass the login control.\n\n\n\n"},{"lang":"es","value":"Asset Management System v1.0 es vulnerable a una vulnerabilidad de Inyección SQL no autenticada en el parámetro 'email' de la página index.php, lo que permite a un atacante externo volcar todo el contenido de la base de datos y omitir el control de inicio de sesión."}],"affected":[{"source":"help@fluidattacks.com","affectedData":[{"vendor":"Asset Management System","product":"Asset Management System","defaultStatus":"unaffected","versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"help@fluidattacks.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-23T18:49:27.671512Z","id":"CVE-2023-43013","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"help@fluidattacks.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:projectworlds:asset_management_system:1.0:*:*:*:*:*:*:*","matchCriteriaId":"656A5C3D-EB26-41B4-8D6A-BE16BE287F05"}]}]}],"references":[{"url":"https://fluidattacks.com/advisories/nergal","source":"help@fluidattacks.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://projectworlds.in/","source":"help@fluidattacks.com","tags":["Product"]},{"url":"https://fluidattacks.com/advisories/nergal","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://projectworlds.in/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}