First published: Mon Aug 07 2023(Updated: )
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file catagory_data.php. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236289 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mayurik Inventory Management System | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4199 is high, with a severity value of 7.5.
The affected software for CVE-2023-4199 is Mayurik Inventory Management System 1.0.
The CWE category for CVE-2023-4199 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
CVE-2023-4199 allows remote attackers to initiate SQL injection attacks by manipulating the argument 'columns[1][data]' in the file catagory_data.php.
To fix CVE-2023-4199, it is recommended to apply the latest security patch or update provided by Mayurik Inventory Management System.