SourceCodester Lost and Found Information System HTTP POST Request sql injection
CVE-2023-3679
9.8CRITICAL
Summary
A vulnerability exists in the SourceCodester Lost and Found Information System version 1.0 due to improper handling of HTTP POST requests within the Master.php component. Specifically, the manipulation of the 'id' parameter can lead to SQL injection attacks, allowing remote adversaries to execute arbitrary SQL commands. This violation of data integrity can result in unauthorized data access and potential data compromise.
Affected Version(s)
Lost and Found Information System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tritium (VulDB User)