Fiche vulnérabilité
CVE-2023-36076 : faille critique pocketmanga smanga (CVSS 9.8)
Description
SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 1 sept. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- pocketmanga smanga