SQL Injection Vulnerability in Sourcecodester Service Provider Management System
CVE-2023-34581
9.8CRITICAL
What is CVE-2023-34581?
The Sourcecodester Service Provider Management System version 1.0 is susceptible to SQL Injection attacks through the 'ID' parameter in the URL path /php-spms/?page=services/view&id=2. Exploitation of this vulnerability allows attackers to manipulate SQL queries executed by the application, potentially leading to unauthorized access to sensitive data or database manipulation. It is critical for users to apply security patches and implement input validation mechanisms to mitigate the risks associated with this vulnerability.