CVE-2023-33677: SQL Injection
Published Mar 6, 2024
·Updated
Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=".
Affected Software
1 affected component
oretnom23 Lost And Found Information System=1.0
Event History
Mar 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33677?
CVE-2023-33677 is classified as a critical vulnerability due to its potential for unauthenticated SQL Injection attacks.
2
How do I fix CVE-2023-33677?
To fix CVE-2023-33677, sanitize and parameterize all SQL queries in the affected system.
3
What systems are affected by CVE-2023-33677?
CVE-2023-33677 affects Sourcecodester Lost and Found Information System version 1.0.
4
What is the impact of CVE-2023-33677?
The impact of CVE-2023-33677 allows attackers to execute arbitrary SQL commands on the database.
5
Is authentication required to exploit CVE-2023-33677?
No, CVE-2023-33677 can be exploited without authentication, making it highly dangerous.