PT-2023-16455 · Sourcecodester · Sourcecodester Online Eyewear Shop

Pconticp

+1

·

Published

2023-02-06

·

Updated

2024-09-07

·

CVE-2023-0686

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Online Eyewear Shop version 1.0
Description A critical issue has been found, affecting the function update cart of the file /oews/classes/Master.php?f=update cart in the HTTP POST Request Handler component. The manipulation of the cart id argument leads to SQL injection, allowing for remote attacks. The complexity of an attack is rather high, and the exploitability is told to be difficult.
Recommendations For SourceCodester Online Eyewear Shop version 1.0, consider disabling the update cart function until a patch is available. Restrict access to the /oews/classes/Master.php?f=update cart endpoint to minimize the risk of exploitation. Avoid using the cart id argument in the affected HTTP POST Request Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-0686

Affected Products

Sourcecodester Online Eyewear Shop