CVE-2023-27205: SQL Injection
Published Mar 9, 2023
·Updated
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/salesreport.php.
Affected Software
2 affected components
Best Pos Management System Project Best Pos Management System=1.0
Mayurik Best Pos Management System=1.0
Event History
Mar 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-27205?
CVE-2023-27205 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2023-27205?
To fix CVE-2023-27205, sanitize and validate user input for the month parameter in the sales_report.php file.
3
What impact does CVE-2023-27205 have on my application?
CVE-2023-27205 can allow an attacker to execute arbitrary SQL queries, potentially compromising the database.
4
Which version of the Best POS Management System is affected by CVE-2023-27205?
CVE-2023-27205 affects version 1.0 of the Best POS Management System.
5
Where is the SQL injection vulnerability located in CVE-2023-27205?
The SQL injection vulnerability in CVE-2023-27205 is located in the month parameter of the /kruxton/sales_report.php file.