SourceCodester Music Gallery Site GET Request Master.php sql injection
CVE-2023-0962

8.8HIGH

Key Information:

Vendor
CVE Published:
22 February 2023

Summary

A vulnerability exists in the SourceCodester Music Gallery Site 1.0, where improper handling of the 'id' parameter in the Master.php file of the GET Request Handler component allows an attacker to execute SQL injection attacks remotely. This flaw could lead to unauthorized access to the database, enabling an attacker to manipulate or retrieve sensitive information. Given its public disclosure, the risk of exploitation is heightened, making it essential for users of this software to apply necessary patches and implement security measures.

Affected Version(s)

Music Gallery Site 1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

navaidansari (VulDB User)
.