SourceCodester Online Computer and Laptop Store GET Parameter sql injection
CVE-2023-2242
8.8HIGH
What is CVE-2023-2242?
A vulnerability exists within SourceCodester's Online Computer and Laptop Store 1.0, specifically relating to its GET Parameter Handler component. By manipulating the argument 'c/s', an attacker is able to execute SQL injection attacks, which can be executed remotely. This vulnerability reveals a critical oversight in input validation, allowing unauthorized access and exploitation of the application's database framework. Security measures and patches are urgently recommended to mitigate associated risks.
Affected Version(s)
Online Computer and Laptop Store 1.0