SourceCodester Vehicle Service Management System view_service.php sql injection
CVE-2023-2092
9.8CRITICAL
Summary
A significant SQL injection vulnerability exists in SourceCodester's Vehicle Service Management System version 1.0. The issue is found in the 'view_service.php' script, where an attacker can manipulate the 'id' argument to execute arbitrary SQL queries. This flaw can potentially allow remote attackers to gain unauthorized access to sensitive data or perform harmful actions on the database. With the exploit now public, organizations utilizing this system should take immediate steps to mitigate the risks associated with this vulnerability.
Affected Version(s)
Vehicle Service Management System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SSL_Seven_Security Lab_WangZhiQiang_XiaoZiLong (VulDB User)