CVE-2023-6312

CWE-89SQL Injection3 documents3 sources
Severity
7.2HIGH
EPSS
0.1%
top 84.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 27

Description

A vulnerability was found in SourceCodester Loan Management System 1.0. It has been classified as critical. Affected is the function delete_user of the file deleteUser.php of the component Users Page. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246138 is the identifier assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 1.2 | Impact: 3.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-42w4-gh3x-8p8w: A vulnerability was found in SourceCodester Loan Management System 12023-11-27
CVEList
SourceCodester Loan Management System Users Page deleteUser.php delete_user sql injection2023-11-27
CVE-2023-6312 (HIGH CVSS 7.2) | A vulnerability was found in Source | cvebase.io