First published: Thu Mar 30 2023(Updated: )
A vulnerability classified as critical was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected by this vulnerability is an unknown functionality of the file passwordrecover.php. The manipulation of the argument phonenumber leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-224623.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe Young Entrepreneur E-negosyo System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1735 is classified as a critical vulnerability.
To fix CVE-2023-1735, ensure to validate and sanitize user inputs in the passwordrecover.php file to prevent SQL injection.
CVE-2023-1735 affects the Young Entrepreneur E-Negosyo System version 1.0.
CVE-2023-1735 is a SQL injection vulnerability associated with the passwordrecover.php functionality.
An attacker exploiting CVE-2023-1735 can manipulate the phonenumber argument to execute unauthorized SQL queries.