CVE-2023-1151

CWE-89SQL Injection8 documents4 sources
Severity
9.8CRITICAL
EPSS
0.3%
top 43.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 2
Latest updateAug 2

Description

A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file administrator.php of the component Cookie Handler. The manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222163.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

🔴Vulnerability Details

7
OSV
linux-oem-6.5 vulnerabilities2024-08-02
OSV
linux-hwe-6.5 vulnerabilities2024-07-17
OSV
linux-azure-6.5, linux-gcp-6.5 vulnerabilities2024-07-16
OSV
linux, linux-gcp, linux-nvidia-6.5, linux-raspi vulnerabilities2024-07-12
OSV
linux-intel-iotg vulnerabilities2024-05-28
CVE-2023-1151 (CRITICAL CVSS 9.8) | A vulnerability was found in Source | cvebase.io