SourceCodester Simple Online Mens Salon Management System sql injection
CVE-2023-3987

9.8CRITICAL

Key Information:

Vendor
CVE Published:
28 July 2023

Summary

The Simple Online Mens Salon Management System version 1.0 by SourceCodester is susceptible to a SQL injection attack. This vulnerability exists in an unspecified function within the user management section of the application (/admin/?page=user/manage_user&id=3). By manipulating the 'id' parameter in a crafted HTTP request, an attacker may execute arbitrary SQL commands against the database, thereby compromising sensitive data. This vulnerability can be exploited remotely, allowing attackers to leverage public-facing services. The method of attack has been publicly disclosed, raising the urgency for users to apply necessary patches or mitigations to safeguard their systems.

Affected Version(s)

Simple Online Mens Salon Management System 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

draco (VulDB User)
.