Campcodes Video Sharing Website admin_class.php sql injection
CVE-2023-2038

7.5HIGH

Key Information:

Vendor
Campcodes
Vendor
CVE Published:
14 April 2023

Summary

A vulnerability has been identified in the Campcodes Video Sharing Website 1.0, where the manipulation of the email argument in the admin_class.php file can be exploited for SQL injection attacks. This flaw enables remote attackers to interact with the application's database and may lead to unauthorized access or data manipulation. The vulnerability has been publicly disclosed, making it imperative for users to implement necessary security measures.

Affected Version(s)

Video Sharing Website 1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SSL_Seven_Security Lab_WangZhiQiang_ZhangYing (VulDB User)
.
CVE-2023-2038 : Campcodes Video Sharing Website admin_class.php sql injection | SecurityVulnerability.io