PT-2023-16648 · Sourcecodester · Sourcecodester Sales Tracker Management System

Mroz1L

·

Publicado

2023-02-22

·

Atualizado

2024-05-17

·

CVE-2023-0964

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Sales Tracker Management System version 1.0
Description A critical vulnerability has been found in the SourceCodester Sales Tracker Management System. The issue is related to an unknown function of the file admin/products/view product.php, where the manipulation of the id argument leads to sql injection. This allows for a remote attack, with a rather high complexity and difficult exploitability.
Recommendations For SourceCodester Sales Tracker Management System version 1.0, consider disabling the id argument in the affected file admin/products/view product.php as a temporary workaround until a patch is available. Restrict access to the view product.php file to minimize the risk of exploitation. Avoid using the id argument in the affected function until the issue is resolved.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-0964

Produtos afetados

Sourcecodester Sales Tracker Management System