Author: Angelo Barbosa

CVE-2023-40058 | SolarWinds Access Rights Manager up to 2023.2.1 Environment access control

A vulnerability was found in SolarWinds Access Rights Manager up to 2023.2.1. It has been classified as critical. This affects an unknown part of the component Environment Handler. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2023-40058. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-48690 | Project Worlds Railway Reservation System 1.0 train.php bynum sql injection

A vulnerability was found in Project Worlds Railway Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file train.php. The manipulation of the argument bynum leads to sql injection. This vulnerability is handled as CVE-2023-48690. The attack may be launched remotely. There is no exploit...

Read More

CVE-2023-48689 | Project Worlds Railway Reservation System 1.0 train.php byname sql injection

A vulnerability has been found in Project Worlds Railway Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file train.php. The manipulation of the argument byname leads to sql injection. This vulnerability is known as CVE-2023-48689. The attack can be launched remotely. There is no exploit...

Read More

CVE-2023-48722 | Project Worlds Student Result Management System 1.0 add_results.php class_name sql injection

A vulnerability, which was classified as critical, was found in Project Worlds Student Result Management System 1.0. Affected is an unknown function of the file add_results.php. The manipulation of the argument class_name leads to sql injection. This vulnerability is traded as CVE-2023-48722. It is possible to launch the attack remotely. There is no exploit...

Read More