SQL Injection Vulnerability in SourceCodester Simple Subscription Website
CVE-2024-4093

8.8HIGH

Key Information:

Vendor
CVE Published:
24 April 2024

Summary

A serious security flaw exists in the Simple Subscription Website 1.0 developed by SourceCodester, specifically within the view_application.php file. This vulnerability enables an attacker to execute SQL injection through improper handling of the 'id' parameter. By exploiting this weakness, malicious users could execute arbitrary SQL queries on the database, potentially leading to data breaches, unauthorized access, or data manipulation. The vulnerability is publicly disclosed, which highlights the urgent need for users and administrators to apply patches or implement security measures promptly to protect their systems from exploitation.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.