SourceCodester Alphaware Simple E-Commerce System admin_index.php sql injection
CVE-2023-1503
8.1HIGH
Summary
A vulnerability has been identified in the SourceCodester Alphaware Simple E-Commerce System 1.0, specifically in the admin/admin_index.php file. The flaw allows attackers to manipulate the username and password input parameters, leading to SQL injection. This vulnerability permits remote exploitation, where malicious actors may execute arbitrary SQL commands through crafted input. While the attack complexity is reported as high, the public disclosure of this exploit increases the urgency for affected users to apply patches and secure their installations.
Affected Version(s)
Alphaware Simple E-Commerce System 1.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
WWesleywww (VulDB User)