Severity
9.8CRITICAL
EPSS
0.1%
top 79.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateOct 2

Description

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file /admin/inventory/manage_stock.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-225406 is the identifier assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
SourceCodester Online Eyewear Shop GET Parameter manage_stock.php sql injection2023-04-10
GHSA
GHSA-cgw5-jvm7-6f73: A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 12023-04-10

📋Vendor Advisories

1
Red Hat
vim: Heap-based Buffer Overflow in trunc_string()2023-10-02
CVE-2023-1969 (CRITICAL CVSS 9.8) | A vulnerability classified as criti | cvebase.io