SourceCodester Complaint Management System POST Parameter registration.php sql injection
CVE-2023-2243
8.8HIGH
Summary
A SQL injection vulnerability was identified in the SourceCodester Complaint Management System 1.0. The issue arises from improper handling of the 'fullname' parameter within the 'users/registration.php' file. An attacker could exploit this flaw remotely, potentially allowing for unauthorized access to the database and manipulation of data. Given that the exploit has been publicly disclosed, it is crucial for users of this system to assess their vulnerability and implement necessary security measures to mitigate risks.
Affected Version(s)
Complaint Management System 1.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
mckayyang (VulDB User)