First published: Mon Nov 27 2023(Updated: )
A vulnerability classified as critical has been found in SourceCodester Free and Open Source Inventory Management System 1.0. Affected is an unknown function of the file /ample/app/ajax/member_data.php. The manipulation of the argument columns leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246132.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-6306 is critical.
CVE-2023-6306 affects SourceCodester Free and Open Source Inventory Management System 1.0.
The vulnerability in SourceCodester Free and Open Source Inventory Management System is a SQL injection in the member_data.php file.
An attacker can exploit CVE-2023-6306 by manipulating the 'columns' argument in the /ample/app/ajax/member_data.php file.
Yes, a fix is available for CVE-2023-6306. It is recommended to update to a patched version of SourceCodester Free and Open Source Inventory Management System.