CVE-2023-5278: SourceCodester Engineers Online Portal login.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument username/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-240906 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5278?
The severity of CVE-2023-5278 is critical.
How does CVE-2023-5278 affect SourceCodester Engineers Online Portal?
CVE-2023-5278 affects SourceCodester Engineers Online Portal 1.0 through an SQL injection vulnerability.
How can an attacker exploit CVE-2023-5278?
An attacker can exploit CVE-2023-5278 by manipulating the username/password argument in the login.php file to launch an SQL injection attack remotely.
Is there a fix available for CVE-2023-5278?
At the moment, there is no available fix for CVE-2023-5278. It is recommended to follow any official security advisories or updates from the vendor.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2023-5278?
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-5278 is CWE-89.