CVE-2023-6305: SourceCodester Free and Open Source Inventory Management System suppliar_data.php sql injection
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file ample/app/ajax/suppliardata.php. The manipulation of the argument columns leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246131.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6305?
The severity of CVE-2023-6305 is critical, with a severity score of 9.8.
How does CVE-2023-6305 affect SourceCodester Free and Open Source Inventory Management System?
CVE-2023-6305 affects SourceCodester Free and Open Source Inventory Management System 1.0 by allowing SQL injection through the file ample/app/ajax/suppliar_data.php.
What is the CWE classification of CVE-2023-6305?
CVE-2023-6305 has a CWE classification of CWE-89 (SQL Injection).
What is the reference for CVE-2023-6305?
The reference for CVE-2023-6305 can be found at the following links: [Link 1](https://vuldb.com/?id.246131), [Link 2](https://vuldb.com/?ctiid.246131), [Link 3](https://github.com/BigTiger2020/2023/blob/main/Free%20and%20Open%20Source%20inventory%20management%20system/Free%20and%20Open%20Source%20inventory%20management%20system.md).
How can I fix CVE-2023-6305?
To fix CVE-2023-6305, you should apply the latest patch or update provided by the vendor for SourceCodester Free and Open Source Inventory Management System 1.0.