CVE-2023-53734
Severity CVSS v4.0:
HIGH
Type:
CWE-89
SQL Injection
Publication date:
04/12/2025
Last modified:
08/12/2025
Description
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/mayuri_k/2022/dawa-pharma-1.0-2022
- https://www.exploit-db.com/exploits/51818
- https://www.mayurik.com/source-code/P0349/best-pharmacy-billing-software-free-download
- https://www.nu11secur1ty.com/
- https://www.vulncheck.com/advisories/dawa-pharma-10-sql-injection-via-email-parameter



