SourceCodester Online Jewelry Store POST Parameter supplier.php sql injection
CVE-2023-2815
9.8CRITICAL
Summary
A security flaw has been identified in the SourceCodester Online Jewelry Store 1.0, specifically within the supplier.php file. This vulnerability arises from inadequate validation of the 'suppid' parameter, allowing an attacker to execute SQL injection attacks. Such manipulation can compromise the integrity of the database, permitting unauthorized access and data manipulation. Since the exploit can be executed remotely, it poses a significant risk to users and their stored information. The vulnerability has been publicly disclosed, increasing the urgency for mitigative action.
Affected Version(s)
Online Jewelry Store 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
likaiwen (VulDB User)