First published: Mon Nov 27 2023(Updated: )
A vulnerability was found in SourceCodester Loan Management System 1.0. It has been classified as critical. Affected is the function delete_user of the file deleteUser.php of the component Users Page. The manipulation of the argument user_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-246138 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Loan Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6312 is a critical SQL injection vulnerability found in the SourceCodester Loan Management System 1.0, specifically in the deleteUser.php file of the Users Page component.
CVE-2023-6312 has a severity rating of 7.2, which is considered high.
The SQL injection vulnerability in deleteUser.php (CVE-2023-6312) occurs due to the manipulation of the user_id argument.
The affected software for CVE-2023-6312 is the SourceCodester Loan Management System 1.0.
It is recommended to apply the latest patch or update provided by the vendor to fix the SQL injection vulnerability in deleteUser.php (CVE-2023-6312).