CVE-2023-53917
EUVD-2023-6019717.12.2025, 23:15
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| powerstonegh | affiliate_me | 5.0.1 |
𝑥
= Vulnerable software versions