CVE-2023-2677: SourceCodester Covid-19 Contact Tracing System manage.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Covid-19 Contact Tracing System 1.0. This affects an unknown part of the file admin/establishment/manage.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-228891.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2677?
CVE-2023-2677 has been classified as a critical vulnerability.
How does CVE-2023-2677 affect the SourceCodester Covid-19 Contact Tracing System?
CVE-2023-2677 allows for SQL injection through the manage.php file, potentially compromising the application's database.
What versions of the SourceCodester Covid-19 Contact Tracing System are affected by CVE-2023-2677?
CVE-2023-2677 affects version 1.0 of the SourceCodester Covid-19 Contact Tracing System.
How can I mitigate CVE-2023-2677 in my application?
To mitigate CVE-2023-2677, validate and sanitize all user inputs to prevent SQL injection attacks.
Is there a patch available for CVE-2023-2677?
As of now, no official patch has been released for CVE-2023-2677, so users should implement immediate security measures.