SourceCodester Online Eyewear Shop sql injection
CVE-2023-0673

8.1HIGH

Key Information:

Vendor
CVE Published:
4 February 2023

Summary

A significant vulnerability was identified in SourceCodester's Online Eyewear Shop version 1.0, specifically within the product view feature. This vulnerability arises from improper handling of the 'id' parameter within the URL path oews/?p=products/view_product.php, allowing attackers to perform SQL injection attacks. Remote attackers can exploit this weakness to manipulate database queries by injecting malicious SQL code. Although the complexity of successfully executing this attack is relatively high, potential security ramifications necessitate immediate attention from users and administrators of the affected product.

Affected Version(s)

Online Eyewear Shop 1.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Pierfrancesco Conti
secpconti (VulDB User)
.