SourceCodester Lost and Found Information System HTTP POST Request sql injection
CVE-2023-3679
9.8CRITICAL
What is CVE-2023-3679?
A vulnerability exists in the SourceCodester Lost and Found Information System version 1.0 due to improper handling of HTTP POST requests within the Master.php component. Specifically, the manipulation of the 'id' parameter can lead to SQL injection attacks, allowing remote adversaries to execute arbitrary SQL commands. This violation of data integrity can result in unauthorized data access and potential data compromise.
Affected Version(s)
Lost and Found Information System 1.0