CVE-2023-1959: SourceCodester Online Computer and Laptop Store sql injection
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=savecategory. The manipulation of the argument category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-225346 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1959?
The severity of CVE-2023-1959 is high with a score of 8.8.
What is the vulnerability in SourceCodester Online Computer and Laptop Store 1.0?
The vulnerability in SourceCodester Online Computer and Laptop Store 1.0 is a SQL injection vulnerability in the file /classes/Master.php?f=save_category.
How does the vulnerability impact the software?
The vulnerability allows for SQL injection, which can be used to manipulate the argument category and potentially compromise the application.
How can I fix the vulnerability in SourceCodester Online Computer and Laptop Store 1.0?
To fix the vulnerability, it is recommended to apply the latest security patches or updates provided by the vendor. Additionally, implementing proper input validation and sanitization can help mitigate the risk of SQL injection attacks.
Where can I find more information about CVE-2023-1959?
You can find more information about CVE-2023-1959 on the following references: [Link 1](https://github.com/boyi0508/Online-Computer-and-Laptop-Store/blob/main/SQL%20injection%20exists%20at%20the%20newly%20added%20category%20list.pdf), [Link 2](https://vuldb.com/?ctiid.225346), [Link 3](https://vuldb.com/?id.225346).