SourceCodester Auto Dealer Management System sql injection
CVE-2023-0913
8.8HIGH
What is CVE-2023-0913?
A SQL injection vulnerability exists in the SourceCodester Auto Dealer Management System 1.0, affecting the /adms/admin/?page=vehicles/sell_vehicle endpoint. This vulnerability enables attackers to manipulate the 'id' argument, allowing unauthorized access to the database. As it can be triggered remotely, this issue poses a significant risk and has been publicly disclosed, making it crucial for users to take immediate action to secure their systems.
Affected Version(s)
Auto Dealer Management System 1.0