PT-2023-25420 · Smanga · Smanga

Tdragon6

·

Published

2023-09-01

·

Updated

2023-09-07

·

CVE-2023-36076

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions smanga versions 3.1.9 and earlier
Description The issue allows remote attackers to execute arbitrary code and gain sensitive information. This is achieved via the mediaId, mangaId, and userId parameters in the "php/history/add.php" endpoint.
Recommendations For smanga versions 3.1.9 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-36076

Affected Products

Smanga