CVE-2023-4184

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICAL
EPSS
0.0%
top 86.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6

Description

A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-236219.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

🔴Vulnerability Details

2
GHSA
GHSA-rf22-xfqf-mwjc: A vulnerability was found in SourceCodester Inventory Management System 12023-08-06
CVEList
SourceCodester Inventory Management System sell_return.php sql injection2023-08-06
CVE-2023-4184 (CRITICAL CVSS 9.8) | A vulnerability was found in Source | cvebase.io