CVE-2023-4200: SourceCodester Inventory Management System product_data.php. sql injection
A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file productdata.php.. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-236290 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4200?
CVE-2023-4200 is a critical vulnerability found in SourceCodester Inventory Management System 1.0 that allows remote SQL injection attacks.
How severe is CVE-2023-4200?
CVE-2023-4200 is classified as critical with a severity rating of 9.8.
How does CVE-2023-4200 affect SourceCodester Inventory Management System?
CVE-2023-4200 affects the file product_data.php and allows remote SQL injection attacks by manipulating the argument columns[1][data].
How can I fix CVE-2023-4200?
To fix CVE-2023-4200, it is recommended to apply the latest patch or update provided by the vendor for the SourceCodester Inventory Management System 1.0.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-4200?
The Common Weakness Enumeration (CWE) ID for CVE-2023-4200 is CWE-89, which refers to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').