CVE-2023-37772: SQL Injection
Published Aug 1, 2023
·Updated
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
Affected Software
2 affected components
Online Shopping Portal Project Online Shopping Portal=3.1
Phpgurukul Online Shopping Portal=3.1
Event History
Aug 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-37772.
2
What is the severity of CVE-2023-37772?
The severity of CVE-2023-37772 is high.
3
What is the affected software version?
The affected software version is Online Shopping Portal Project v3.1.
4
How can the SQL injection vulnerability be exploited?
The SQL injection vulnerability can be exploited via the Email parameter at /shopping/login.php.
5
Are there any references related to CVE-2023-37772?
Yes, you can find references related to CVE-2023-37772 at http://phpgurukul.com/shopping-portal-free-download/, https://phpgurukul.com/, and https://github.com/anky-123/CVE-2023-37772/blob/main/CVE-2.