PT-2023-16648 · Sourcecodester · Sourcecodester Sales Tracker Management System

Mroz1L

·

Published

2023-02-22

·

Updated

2024-05-17

·

CVE-2023-0964

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Sales Tracker Management System version 1.0
Description A critical vulnerability has been found in the SourceCodester Sales Tracker Management System. The issue is related to an unknown function of the file admin/products/view product.php, where the manipulation of the id argument leads to sql injection. This allows for a remote attack, with a rather high complexity and difficult exploitability.
Recommendations For SourceCodester Sales Tracker Management System version 1.0, consider disabling the id argument in the affected file admin/products/view product.php as a temporary workaround until a patch is available. Restrict access to the view product.php file to minimize the risk of exploitation. Avoid using the id argument in the affected function until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-0964

Affected Products

Sourcecodester Sales Tracker Management System