SourceCodester Online Eyewear Shop sql injection
CVE-2023-0673
8.1HIGH
Summary
A significant vulnerability was identified in SourceCodester's Online Eyewear Shop version 1.0, specifically within the product view feature. This vulnerability arises from improper handling of the 'id' parameter within the URL path oews/?p=products/view_product.php, allowing attackers to perform SQL injection attacks. Remote attackers can exploit this weakness to manipulate database queries by injecting malicious SQL code. Although the complexity of successfully executing this attack is relatively high, potential security ramifications necessitate immediate attention from users and administrators of the affected product.
Affected Version(s)
Online Eyewear Shop 1.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Pierfrancesco Conti
secpconti (VulDB User)