SourceCodester Clinics Patient Management System update_user.php sql injection
CVE-2023-1035
Key Information:
- Vendor
SourceCodester
- Vendor
- CVE Published:
- 25 February 2023
Badges
What is CVE-2023-1035?
A SQL injection vulnerability exists in the SourceCodester Clinics Patient Management System 1.0 due to improper handling of the user_id parameter in the update_user.php file. This issue allows an attacker to execute arbitrary SQL commands, which can potentially compromise the database. The vulnerability can be exploited remotely, creating a significant security risk. Users are advised to apply patches or updates provided by the vendor to mitigate the risk associated with this SQL injection vulnerability.
Affected Version(s)
Clinics Patient Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved