SourceCodester Simple Membership System delete_member.php sql injection
CVE-2023-4846
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 9 September 2023
Badges
What is CVE-2023-4846?
A security flaw in the Simple Membership System 1.0 allows an attacker to manipulate parameters in the delete_member.php file, leading to SQL injection vulnerabilities. This manipulation, specifically targeting the mem_id argument, can be exploited remotely, potentially giving attackers unauthorized access to the database. The vulnerability is publicly disclosed, raising concerns about the impact it may have on the security of affected systems.
Affected Version(s)
Simple Membership System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved