First published: Mon Nov 27 2023(Updated: )
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file ample/app/ajax/suppliar_data.php. The manipulation of the argument columns leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246131.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-6305 is critical, with a severity score of 9.8.
CVE-2023-6305 affects SourceCodester Free and Open Source Inventory Management System 1.0 by allowing SQL injection through the file ample/app/ajax/suppliar_data.php.
CVE-2023-6305 has a CWE classification of CWE-89 (SQL Injection).
The reference for CVE-2023-6305 can be found at the following links: [Link 1](https://vuldb.com/?id.246131), [Link 2](https://vuldb.com/?ctiid.246131), [Link 3](https://github.com/BigTiger2020/2023/blob/main/Free%20and%20Open%20Source%20inventory%20management%20system/Free%20and%20Open%20Source%20inventory%20management%20system.md).
To fix CVE-2023-6305, you should apply the latest patch or update provided by the vendor for SourceCodester Free and Open Source Inventory Management System 1.0.