CVE-2023-3859: phpscriptpoint Car Listing GET Parameter search.php sql injection
A vulnerability was found in phpscriptpoint Car Listing 1.6 and classified as critical. This issue affects some unknown processing of the file /search.php of the component GET Parameter Handler. The manipulation of the argument brandid/modelid/carcondition/carcategoryid/bodytypeid/fueltypeid/transmissiontypeid/year/mileagestart/mileageend/country/state/city leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-235211. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3859?
CVE-2023-3859 is classified as a critical vulnerability affecting Phpscriptpoint Car Listing 1.6.
How do I fix CVE-2023-3859?
To fix CVE-2023-3859, you should update Phpscriptpoint Car Listing to the latest patched version.
What component is affected by CVE-2023-3859?
CVE-2023-3859 affects the GET Parameter Handler in the /search.php file.
What impact does CVE-2023-3859 have?
The impact of CVE-2023-3859 includes potential unauthorized manipulation of user-supplied inputs.
Which version of Phpscriptpoint Car Listing is vulnerable to CVE-2023-3859?
Version 1.6 of Phpscriptpoint Car Listing is vulnerable to CVE-2023-3859.