SourceCodester Best POS Management System sql injection
CVE-2023-0946
9.8CRITICAL
Summary
A SQL injection vulnerability exists in the SourceCodester Best POS Management System 1.0, specifically within the billing/index.php file when manipulating the 'id' parameter. This flaw allows attackers to execute arbitrary SQL queries, potentially compromising the database's integrity. The attack can be executed remotely, making it essential for users and administrators to apply security patches and implement proper input validation to mitigate the risk.
Affected Version(s)
Best POS Management System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
mroz1l (VulDB User)