SourceCodester Online Computer and Laptop Store products.php sql injection
CVE-2023-5374
9.8CRITICAL
Summary
A significant SQL injection vulnerability has been discovered in the products.php file of the Online Computer and Laptop Store application. This flaw allows attackers to manipulate the input argument 'c', enabling them to execute unauthorized SQL code on the database. The vulnerability is exploitable remotely, facilitating potential data breaches and unauthorized access to sensitive information. It is crucial for users of the impacted version to take immediate action to secure their systems against possible exploits.
Affected Version(s)
Online Computer and Laptop Store 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
llixixioo (VulDB User)