First published: Wed Oct 04 2023(Updated: )
A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is the function register of the file Master.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-241254 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Online Computer And Laptop Store | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5373 is a critical vulnerability found in SourceCodester Online Computer and Laptop Store 1.0, which allows for remote SQL injection through the 'register' function in the 'Master.php' file.
CVE-2023-5373 has a severity rating of 9.8 (critical).
CVE-2023-5373 affects the 'register' function in the 'Master.php' file of SourceCodester Online Computer and Laptop Store 1.0, allowing for remote SQL injection.
The SQL injection vulnerability in CVE-2023-5373 can be exploited by manipulating the 'email' argument in the 'register' function of the 'Master.php' file.
To mitigate the CVE-2023-5373 vulnerability, it is recommended to update SourceCodester Online Computer and Laptop Store to a patched version that fixes the SQL injection issue.