CVE-2023-3876: Campcodes Beauty Salon Management System search-appointment.php sql injection
A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235238 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3876?
CVE-2023-3876 is classified as a critical vulnerability.
How does CVE-2023-3876 affect the Campcodes Beauty Salon Management System?
CVE-2023-3876 affects the searchdata argument in the /admin/search-appointment.php file, leading to SQL injection.
What could an attacker achieve by exploiting CVE-2023-3876?
An attacker exploiting CVE-2023-3876 could manipulate SQL queries and potentially gain unauthorized access to sensitive database information.
How do I fix CVE-2023-3876 in the Beauty Salon Management System?
To fix CVE-2023-3876, sanitize and validate the searchdata input to prevent SQL injection.
What versions of Beauty Salon Management System are affected by CVE-2023-3876?
CVE-2023-3876 affects version 1.0 of the Campcodes Beauty Salon Management System.