First published: Mon Nov 27 2023(Updated: )
A vulnerability has been found in SourceCodester Loan Management System 1.0 and classified as critical. This vulnerability affects the function delete_borrower of the file deleteBorrower.php. The manipulation of the argument borrower_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246136.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Loan Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6310 is a critical vulnerability found in SourceCodester Loan Management System 1.0 that allows for SQL injection through the delete_borrower function in the deleteBorrower.php file.
CVE-2023-6310 has a severity rating of 7.2, which is classified as high.
SourceCodester Loan Management System version 1.0 is affected by CVE-2023-6310.
CVE-2023-6310 can be exploited remotely by manipulating the borrower_id argument in the delete_borrower function to perform SQL injection.
At the moment, there is no available fix for CVE-2023-6310. It is recommended to update to a patched version or apply a workaround if provided by the vendor.