PT-2023-17243 · Sourcecodester · Sourcecodester Earnings/Expense Tracker App

Aallll

·

Publicado

2023-03-31

·

Atualizado

2024-05-17

·

CVE-2023-1785

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Earnings and Expense Tracker App version 1.0
Description A critical issue was found in the SourceCodester Earnings and Expense Tracker App, affecting an unknown function of the file manage user.php. The manipulation of the id argument leads to sql injection, allowing for remote attacks.
Recommendations For version 1.0, consider disabling the function that handles the id argument in the manage user.php file until a patch is available. Restrict access to the manage user.php file to minimize the risk of exploitation. Avoid using the id argument in affected API endpoints until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1785

Produtos afetados

Sourcecodester Earnings/Expense Tracker App