CVE-2023-1735: SourceCodester Young Entrepreneur E-Negosyo System passwordrecover.php sql injection
A vulnerability classified as critical was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected by this vulnerability is an unknown functionality of the file passwordrecover.php. The manipulation of the argument phonenumber leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-224623.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1735?
CVE-2023-1735 is classified as a critical vulnerability.
How do I fix CVE-2023-1735?
To fix CVE-2023-1735, ensure to validate and sanitize user inputs in the passwordrecover.php file to prevent SQL injection.
What software is affected by CVE-2023-1735?
CVE-2023-1735 affects the Young Entrepreneur E-Negosyo System version 1.0.
What type of vulnerability is CVE-2023-1735?
CVE-2023-1735 is a SQL injection vulnerability associated with the passwordrecover.php functionality.
What can an attacker do with CVE-2023-1735?
An attacker exploiting CVE-2023-1735 can manipulate the phonenumber argument to execute unauthorized SQL queries.