SourceCodester Best Courier Management System view_parcel.php sql injection
CVE-2023-5270
8.8HIGH
Summary
A vulnerability in the SourceCodester Best Courier Management System's view_parcel.php file enables an attacker to manipulate the argument 'id', leading to SQL injection. This allows unauthorized access to sensitive data within the application. The exploit has been publicly disclosed, raising concerns for users of version 1.0 and potentially exposing them to further attacks.
Affected Version(s)
Best Courier Management System 1.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SSL_Seven_Security Lab_WangZhiQiang_XiaoZiLong (VulDB User)