CVE-2023-1498: code-projects Responsive Hotel Site Newsletter Log messages.php sql injection
A vulnerability classified as critical has been found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file messages.php of the component Newsletter Log Handler. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-223398 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1498?
CVE-2023-1498 is classified as a critical vulnerability.
What component is affected by CVE-2023-1498?
CVE-2023-1498 affects the Newsletter Log Handler in the messages.php file.
What type of vulnerability is CVE-2023-1498?
CVE-2023-1498 is identified as an SQL injection vulnerability.
How do I fix CVE-2023-1498?
To fix CVE-2023-1498, you should validate and sanitize user inputs within the title argument to prevent SQL injection.
What software versions are impacted by CVE-2023-1498?
CVE-2023-1498 impacts version 1.0 of the Responsive Hotel Site.