SourceCodester Online Computer and Laptop Store save_brand sql injection
CVE-2023-1985
7.2HIGH
What is CVE-2023-1985?
A SQL injection vulnerability exists in the Online Computer and Laptop Store 1.0 due to improper input handling in the save_brand function located in /classes/Master.php?f=save_brand. Attackers can exploit this flaw remotely by manipulating the 'name' argument, potentially leading to unauthorized database access and data manipulation. The issue has been publicly disclosed and could be leveraged by malicious entities.
Affected Version(s)
Online Computer and Laptop Store 1.0