SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.
References
| Link | Resource |
|---|---|
| https://gist.github.com/nguyenkhanhthuan/03ce706686508b14506d38788c754dfb | Exploit Third Party Advisory |
| https://github.com/ThuanNguyen115685/Report/blob/main/sqlinjection.md | Broken Link |
Configurations
History
18 Dec 2025, 22:33
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Anirbandutta9 news-buzz
Anirbandutta9 |
|
| CPE | cpe:2.3:a:anirbandutta9:news-buzz:1.0:*:*:*:*:*:*:* | |
| References | () https://gist.github.com/nguyenkhanhthuan/03ce706686508b14506d38788c754dfb - Exploit, Third Party Advisory | |
| References | () https://github.com/ThuanNguyen115685/Report/blob/main/sqlinjection.md - Broken Link |
15 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-15 21:15
Updated : 2025-12-18 22:33
NVD link : CVE-2023-38913
Mitre link : CVE-2023-38913
CVE.ORG link : CVE-2023-38913
JSON object : View
Products Affected
anirbandutta9
- news-buzz
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
