Advisories

Publicly disclosed vulnerabilities discovered by Fluid Attacks Research Team.

Severity 7.1

Book Stack v23.10.2 - LFR via Blind SSRF

CVE-2023-6199

Published: 2023-11-20 12:00 COT

Discovered by Carlos Bello

Severity 9.1

Dev Blog v1.0 - ATO

CVE-2023-6144

Published: 2023-11-15 12:00 COT

Discovered by Carlos Bello

Severity 6.4

Dev Blog v1.0 - Stored XSS

CVE-2023-6142

Published: 2023-11-15 12:00 COT

Discovered by Carlos Bello

Severity 8.8

Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi)

CVE-2023-45115,CVE-2023-45116,CVE-2023-45117,CVE-2023-45118,CVE-2023-45119,CVE-2023-45120,CVE-2023-45121,CVE-2023-45122,CVE-2023-45123,CVE-2023-45124,CVE-2023-45125,CVE-2023-45126,CVE-2023-45127

Published: 2023-11-02 12:00 COT

Discovered by Andres Roldan

Severity 9.8

Online Job Portal v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

CVE-2023-46676,CVE-2023-46677,CVE-2023-46678,CVE-2023-46679,CVE-2023-46680

Published: 2023-11-02 12:00 COT

Discovered by Andres Roldan

Severity 9.8

Online Matrimonial Project v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

CVE-2023-46785,CVE-2023-46786,CVE-2023-46787,CVE-2023-46788,CVE-2023-46789,CVE-2023-46790,CVE-2023-46791,CVE-2023-46792,CVE-2023-46793,CVE-2023-46794,CVE-2023-46795,CVE-2023-46796,CVE-2023-46797,CVE-2023-46798,CVE-2023-46799,CVE-2023-46800

Published: 2023-11-02 12:00 COT

Discovered by Andres Roldan

Severity 9.8

Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

CVE-2023-45323,CVE-2023-45324,CVE-2023-45325,CVE-2023-45326,CVE-2023-45327,CVE-2023-45328,CVE-2023-45329,CVE-2023-45330,CVE-2023-45331,CVE-2023-45332,CVE-2023-45333,CVE-2023-45334,CVE-2023-45335,CVE-2023-45336,CVE-2023-45337,CVE-2023-45338,CVE-2023-45339,CVE-2023-45340,CVE-2023-45341,CVE-2023-45342,CVE-2023-45343,CVE-2023-45344,CVE-2023-45345,CVE-2023-45346,CVE-2023-45347

Published: 2023-11-01 12:00 COT

Discovered by Andres Roldan

Severity 9.8

Online Bus Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

CVE-2023-45012,CVE-2023-45013,CVE-2023-45014,CVE-2023-45015,CVE-2023-45016,CVE-2023-45017,CVE-2023-45018,CVE-2023-45019

Published: 2023-11-01 12:00 COT

Discovered by Andres Roldan

Severity 9.8

Online Examination System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)

CVE-2023-45111,CVE-2023-45112,CVE-2023-45113,CVE-2023-45114

Published: 2023-11-01 12:00 COT

Discovered by Andres Roldan

For more information, you can read our Disclosure Policy

Fluid Logo Footer

Hacking software for over 20 years

Fluid Attacks tests applications and other systems, covering all software development stages. Our team assists clients in quickly identifying and managing vulnerabilities to reduce the risk of incidents and deploy secure technology.

Copyright © 0 Fluid Attacks. We hack your software. All rights reserved.