Medium severity6.5NVD Advisory· Published Dec 17, 2025· Updated Jun 17, 2026
CVE-2023-53917
CVE-2023-53917
Description
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: = 5.0.1
5.0.1+ 1 more
- (no CPE)range: 5.0.1
- cpe:2.3:a:powerstonegh:affiliate_me:5.0.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51468nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/affiliate-me-sql-injection-vulnerability-via-admin-panelnvdThird Party Advisory
- www.powerstonegh.comnvdProduct
News mentions
0No linked articles in our index yet.