SourceCodester Simple Online Mens Salon Management System sql injection
CVE-2023-3987
Summary
The Simple Online Mens Salon Management System version 1.0 by SourceCodester is susceptible to a SQL injection attack. This vulnerability exists in an unspecified function within the user management section of the application (/admin/?page=user/manage_user&id=3). By manipulating the 'id' parameter in a crafted HTTP request, an attacker may execute arbitrary SQL commands against the database, thereby compromising sensitive data. This vulnerability can be exploited remotely, allowing attackers to leverage public-facing services. The method of attack has been publicly disclosed, raising the urgency for users to apply necessary patches or mitigations to safeguard their systems.
Affected Version(s)
Simple Online Mens Salon Management System 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved