SourceCodester Billing Management System POST Parameter ajax_service.php sql injection
CVE-2023-2595
9.8CRITICAL
What is CVE-2023-2595?
A vulnerability in the SourceCodester Billing Management System exposes the ajax_service.php file to SQL injection via improper handling of the 'drop_services' parameter. This weakness allows attackers to execute unauthorized SQL commands, potentially compromising sensitive data. The attack can be executed remotely, increasing the risk of exploitation. Awareness and timely remediation are essential, especially since the details of this vulnerability have been made public.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Billing Management System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
yastar (VulDB User)
