Campcodes Retro Cellphone Online Store edit_product.php sql injection
CVE-2023-3473
9.8CRITICAL
Summary
A SQL injection vulnerability has been identified in the Campcodes Retro Cellphone Online Store version 1.0. The issue arises from the manipulation of the 'username' parameter in the /admin/edit_product.php file. This vulnerability allows attackers to execute arbitrary SQL commands remotely, which could compromise sensitive user information. The exploit has been publicly disclosed, heightening the urgency for remediation to protect against potential attacks.
Affected Version(s)
Retro Cellphone Online Store 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lorraine (VulDB User)