CVE-2023-27204: SQL Injection
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manageuser.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27204?
CVE-2023-27204 is classified as a high severity vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
How do I fix CVE-2023-27204?
To fix CVE-2023-27204, validate and sanitize the input for the 'id' parameter in the manage_user.php file before processing database queries.
What impact does CVE-2023-27204 have?
CVE-2023-27204 can allow attackers to manipulate SQL queries, which may result in data leakage or data manipulation.
Is CVE-2023-27204 present in other versions of the Best POS Management System?
CVE-2023-27204 is specifically identified in version 1.0 of the Best POS Management System and may not apply to other versions.
Who is affected by CVE-2023-27204?
Any user or organization using version 1.0 of the Best POS Management System is potentially affected by CVE-2023-27204.