CVE-2023-1985: SourceCodester Online Computer and Laptop Store save_brand sql injection
A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. This issue affects the function savebrand of the file /classes/Master.php?f=savebrand. The manipulation of the argument name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225533 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1985?
The severity of CVE-2023-1985 is high with a severity value of 7.2.
What is the affected software of CVE-2023-1985?
The affected software of CVE-2023-1985 is Oretnom23 Online Computer And Laptop Store version 1.0.
How does CVE-2023-1985 affect SourceCodester Online Computer and Laptop Store?
CVE-2023-1985 affects SourceCodester Online Computer and Laptop Store through a SQL injection vulnerability in the save_brand function of the Master.php file.
How can the SQL injection vulnerability in CVE-2023-1985 be exploited?
The SQL injection vulnerability in CVE-2023-1985 can be exploited by manipulating the 'name' argument in the save_brand function.
Is there a fix for CVE-2023-1985?
The fix for CVE-2023-1985 may involve applying a patch or update provided by the software developer to address the SQL injection vulnerability.