Campcodes Online College Library System Search index.php sql injection
CVE-2023-7156
9.8CRITICAL
Summary
A SQL Injection vulnerability has been identified in Campcodes Online College Library System 1.0, particularly within the Search component's index.php file. The flaw arises due to inadequate validation of the 'category' parameter, which allows an unauthorized attacker to manipulate SQL queries. This vulnerability can be exploited remotely, posing significant security risks as it could lead to unauthorized data access and potential data compromise. Public disclosure of this exploit means attackers may attempt to exploit affected instances without proper safeguards.
Affected Version(s)
Online College Library System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
heishou (VulDB User)