SourceCodester E-Commerce System login.php sql injection
CVE-2023-1506
8.1HIGH
What is CVE-2023-1506?
An SQL injection vulnerability has been identified in the SourceCodester E-Commerce System 1.0, specifically within an unknown function in the login.php file. This vulnerability occurs due to improper handling of the U_USERNAME parameter, allowing attackers to manipulate database queries. The attack can be executed remotely, posing a significant threat to data integrity and confidentiality. Although the complexity of the attack is considered high, the potential for exploitation remains, and the vulnerability has been publicly disclosed, necessitating immediate attention from affected users.
Affected Version(s)
E-Commerce System 1.0
