SourceCodester Vehicle Service Management System view_service.php sql injection
CVE-2023-2092

9.8CRITICAL

Key Information:

Vendor
CVE Published:
15 April 2023

Summary

A significant SQL injection vulnerability exists in SourceCodester's Vehicle Service Management System version 1.0. The issue is found in the 'view_service.php' script, where an attacker can manipulate the 'id' argument to execute arbitrary SQL queries. This flaw can potentially allow remote attackers to gain unauthorized access to sensitive data or perform harmful actions on the database. With the exploit now public, organizations utilizing this system should take immediate steps to mitigate the risks associated with this vulnerability.

Affected Version(s)

Vehicle Service Management System 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SSL_Seven_Security Lab_WangZhiQiang_XiaoZiLong (VulDB User)
.