PT-2023-18868 · Unknown · Art Gallery Management System Project

Rahul Patwari

·

Published

2023-02-10

·

Updated

2023-12-20

·

CVE-2023-23162

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Art Gallery Management System Project version 1.0
Description A SQL injection issue was found in the product.php file, specifically via the cid parameter.
Recommendations For version 1.0, avoid using the cid parameter in the product.php file until the issue is resolved. As a temporary workaround, consider restricting access to the product.php file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23162

Affected Products

Art Gallery Management System Project