Affiliate Me 5.0.1 SQL Injection Vulnerability via Admin Panel
Vulnerability Description
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53917
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- h4ck3r - Faisal Albuloushi
Affected Vendor
powerstonegh
View all reports →