Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Appledog

#14451of 53,622
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2023-24933
9.8
2023-06-29
Sourcecodester · Sourcecodester Shopping Website · CVE-2023-3458
**Name of the Vulnerable Software and Affected Versions** SourceCodester Shopping Website version 1.0 **Description** A critical issue has been found in the forgot-password.php file, where the manipulation of the `contact` argument leads to SQL injection. This issue can be exploited remotely. **Recommendations** For version 1.0, consider disabling the forgot-password.php file or restricting access to it until a patch is available. Avoid using the `contact` argument in the affected file to minimize the risk of exploitation.
PT-2022-22204
8.8
2022-07-28
Unknown · Barangay Management System · CVE-2022-34557
**Name of the Vulnerable Software and Affected Versions** Barangay Management System version 1.0 **Description** A SQL injection issue was found in the Barangay Management System. The vulnerability can be exploited via the `hidden id` parameter at the "/pages/permit/permit.php" API endpoint. **Recommendations** For Barangay Management System version 1.0, consider restricting access to the "/pages/permit/permit.php" endpoint until a fix is available, and avoid using the `hidden id` parameter to minimize the risk of exploitation.