CVE-2023-3502: SourceCodester Shopping Website search-result.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unknown function of the file search-result.php. The manipulation of the argument product leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-232950 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3502?
CVE-2023-3502 is classified as a critical vulnerability.
How does CVE-2023-3502 affect the application?
CVE-2023-3502 allows for SQL injection through the product argument in search-result.php.
Who is affected by CVE-2023-3502?
CVE-2023-3502 affects users of SourceCodester Shopping Website version 1.0.
Can CVE-2023-3502 be exploited remotely?
Yes, CVE-2023-3502 can be exploited remotely by manipulating the product argument.
How do I fix CVE-2023-3502?
To fix CVE-2023-3502, sanitize and validate user inputs to prevent SQL injection.