SourceCodester Complaint Management System POST Parameter registration.php sql injection
CVE-2023-2243

8.8HIGH

Key Information:

Vendor
CVE Published:
22 April 2023

Summary

A SQL injection vulnerability was identified in the SourceCodester Complaint Management System 1.0. The issue arises from improper handling of the 'fullname' parameter within the 'users/registration.php' file. An attacker could exploit this flaw remotely, potentially allowing for unauthorized access to the database and manipulation of data. Given that the exploit has been publicly disclosed, it is crucial for users of this system to assess their vulnerability and implement necessary security measures to mitigate risks.

Affected Version(s)

Complaint Management System 1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mckayyang (VulDB User)
.