First published: Thu Mar 09 2023(Updated: )
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Best POS Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27204 is classified as a high severity vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
To fix CVE-2023-27204, validate and sanitize the input for the 'id' parameter in the manage_user.php file before processing database queries.
CVE-2023-27204 can allow attackers to manipulate SQL queries, which may result in data leakage or data manipulation.
CVE-2023-27204 is specifically identified in version 1.0 of the Best POS Management System and may not apply to other versions.
Any user or organization using version 1.0 of the Best POS Management System is potentially affected by CVE-2023-27204.