PT-2022-8722 · Sourcecodester · Sourcecodester Mobile Shop System

Published

2022-01-28

·

Updated

2023-02-27

·

CVE-2020-25905

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Mobile Shop System in PHP MySQL version 1.0
Description An SQL Injection issue exists in the system via the email parameter in the "login.php" or "LoginAsAdmin.php" files. This allows for potential exploitation.
Recommendations For version 1.0, consider restricting access to the login.php and LoginAsAdmin.php files until a patch is available. As a temporary workaround, avoid using the email parameter in these files to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-25905

Affected Products

Sourcecodester Mobile Shop System