← volver
CVE-2023-0964

SourceCodester Sales Tracker Management System view_product.php sql injection

CVSS 5 MEDIUMEPSS 0.5%CWE-89
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
22 feb 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. Affected is an unknown function of the file admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. VDB-221634 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →