CVE-2023-5033

Source
https://cve.org/CVERecord?id=CVE-2023-5033
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5033.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-5033
Published
2023-09-18T04:31:04.707Z
Modified
2026-07-15T01:49:17.816171258Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
OpenRapid RapidCMS cate-edit-run.php sql injection
Details

A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /admin/category/cate-edit-run.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239877 was assigned to this vulnerability.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5033.json",
    "cwe_ids": [
        "CWE-89"
    ],
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.3.1"
                },
                {
                    "last_affected": "1.3.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/openrapid/rapidcms

Affected ranges

Type
GIT
Repo
https://github.com/openrapid/rapidcms
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.3.1"
        },
        {
            "last_affected": "1.3.1"
        }
    ],
    "cpe": "cpe:2.3:a:openrapid:rapidcms:1.3.1:*:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

1.*
1.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5033.json"