CVE-2023-0903

CWE-89SQL Injection4 documents4 sources
Severity
8.8HIGH
EPSS
0.4%
top 41.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateApr 6

Description

A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file edit-task.php. The manipulation of the argument task_id leads to sql injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221452.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.6 | Impact: 3.4

🔴Vulnerability Details

2
CVEList
SourceCodester Employee Task Management System edit-task.php sql injection2023-02-18
GHSA
GHSA-fxwh-5m79-c73p: A vulnerability was found in SourceCodester Employee Task Management System 12023-02-18

💥Exploits & PoCs

1
Exploit-DB
Employee Task Management System v1.0 - SQL Injection on edit-task.php2023-04-06
CVE-2023-0903 (HIGH CVSS 8.8) | A vulnerability was found in Source | cvebase.io