PT-2023-20372 · Sourcecodester · Sourcecodester Food Ordering Management System
Dewanritik
·
Publicado
2023-05-09
·
Atualizado
2024-09-07
·
CVE-2023-2594
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Food Ordering Management System version 1.0
Description
A critical issue was found in the Registration component, where the manipulation of the
username argument leads to SQL injection. This can be exploited remotely.Recommendations
For SourceCodester Food Ordering Management System version 1.0, consider restricting access to the Registration component until a fix is available. As a temporary workaround, avoid using the
username argument in the affected function to minimize the risk of exploitation.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sourcecodester Food Ordering Management System