Campcodes Beauty Salon Management System index.php sql injection
CVE-2023-3873
7.3HIGH
Summary
A security issue has been identified in Campcodes Beauty Salon Management System 1.0, specifically within the processing of the file /admin/index.php. This vulnerability allows for SQL injection via manipulation of the 'username' argument, enabling remote attackers to execute arbitrary SQL commands. Given its public disclosure, it is essential for users of this system to patch or mitigate their vulnerabilities promptly to protect against potential exploits.
Affected Version(s)
Beauty Salon Management System 1.0
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
xiafine (VulDB User)