CVE-2023-4199: SourceCodester Inventory Management System catagory_data.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file catagorydata.php. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236289 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4199?
The severity of CVE-2023-4199 is high, with a severity value of 7.5.
What is the affected software for CVE-2023-4199?
The affected software for CVE-2023-4199 is Mayurik Inventory Management System 1.0.
What is the CWE category for CVE-2023-4199?
The CWE category for CVE-2023-4199 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
How does CVE-2023-4199 impact the system?
CVE-2023-4199 allows remote attackers to initiate SQL injection attacks by manipulating the argument 'columns[1][data]' in the file catagory_data.php.
How can I fix CVE-2023-4199?
To fix CVE-2023-4199, it is recommended to apply the latest security patch or update provided by Mayurik Inventory Management System.