PT-2022-22968 · Sourcecodester · Sourcecodester Canteen Management System

Joinia

·

Published

2022-10-18

·

Updated

2022-10-19

·

CVE-2022-3584

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Canteen Management System version 1.0
Description A critical issue affects the processing of the file edituser.php, where the manipulation of the id argument leads to SQL injection. This issue can be initiated remotely.
Recommendations For SourceCodester Canteen Management System version 1.0, consider restricting access to the edituser.php file until a fix is available, and avoid using the id argument in this context to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Neutralization

Weakness Enumeration

Related Identifiers

CVE-2022-3584

Affected Products

Sourcecodester Canteen Management System