code-projects Client Details System HTTP POST Request admin sql injection
CVE-2023-7138
Key Information:
- Vendor
- Code-projects
- Status
- Vendor
- CVE Published:
- 28 December 2023
Badges
Summary
A vulnerability exists in the Code-Projects Client Details System, specifically in the HTTP POST Request Handler located in the /admin directory. An attacker can exploit this flaw by manipulating the 'username' argument, potentially leading to unauthorized access to sensitive database information. This vulnerability has been publicly disclosed, which increases the risk of exploitation in the wild. Users of the affected version should apply patches or updates immediately to mitigate these risks.
Affected Version(s)
Client Details System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved