SourceCodester Online Computer and Laptop Store Master.php sql injection
CVE-2023-2661
9.8CRITICAL
What is CVE-2023-2661?
A vulnerability exists in SourceCodester Online Computer and Laptop Store version 1.0 due to improper handling of input parameters in the file /classes/Master.php. This flaw allows attackers to manipulate the 'id' argument, enabling them to execute unauthorized SQL queries. The exploitation can be performed remotely, highlighting a significant risk for exposed web applications. Public disclosure of the exploit increases the urgency for affected users to implement mitigations.
Affected Version(s)
Online Computer and Laptop Store 1.0