SourceCodester Loan Management System Loan Type Page delete_ltype.php delete_ltype sql injection
CVE-2023-6311
7.2HIGH
What is CVE-2023-6311?
A vulnerability in the SourceCodester Loan Management System version 1.0 allows for SQL injection via the delete_ltype function in delete_ltype.php, specifically through the ltype_id argument. This weakness can be exploited by attackers remotely. The public disclosure of this vulnerability raises significant concerns regarding potential unauthorized database access and the integrity of sensitive data. Users of the affected system are strongly advised to implement mitigations and monitor for any unusual activity.
Affected Version(s)
Loan Management System 1.0