SourceCodester Simple Book Catalog App delete_book.php sql injection
CVE-2023-4848
6.3MEDIUM
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 9 September 2023
Summary
A vulnerability classified as critical was found in SourceCodester Simple Book Catalog App 1.0. Affected by this vulnerability is an unknown functionality of the file delete_book.php. The manipulation of the argument delete leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239257 was assigned to this vulnerability.
Affected Version(s)
Simple Book Catalog App 1.0
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
gikaku (VulDB User)