CVE | CVE-2023-1502 |
CVE Title | |
Published Date | 2023-03-20T09:15Z |
Modified Date | 2023-03-23T13:36Z |
CWE Type | CWE-89 |
CVSS 3.x | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Description | A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file function/edit_customer.php. The manipulation of the argument firstname/mi/lastname with the input a' RLIKE SLEEP(5) AND 'dAbu'='dAbu leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-223406 is the identifier assigned to this vulnerability. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://vuldb.com/?id.223406 |
Reference Description | MISC https://vuldb.com/?id.223406 |
Reference URL | https://vuldb.com/?ctiid.223406 |
Reference Description | MISC https://vuldb.com/?ctiid.223406 |
Tags | Exploit Third Party Advisory |
Sources | NIST MITRE |