PT-2025-51955 · Unknown · Affiliate Me

CVE-2023-53917

·

Published

2025-12-17

·

Updated

2025-12-20

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Affiliate Me version 5.0.1
Description The software contains a SQL injection issue in the admin.php endpoint. Authenticated administrators can manipulate database queries through the id parameter using crafted union-based queries. This allows attackers to extract sensitive user information, including usernames and password hashes.
Recommendations Apply a fix for Affiliate Me version 5.0.1 to address the SQL injection issue in the admin.php endpoint.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-53917

Affected Products

Affiliate Me