CVE-2023-7096: code-projects Faculty Management System crud.php sql injection
Published Dec 25, 2023
·Updated
A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. This manipulation of the argument fieldname/tablename causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Carmelogarcia Faculty Management System=1.0
Event History
Dec 25, 2023
CVE Published
01:00 AM
Data Sourced
01:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-7096?
CVE-2023-7096 has been rated as critical.
2
What type of vulnerability is described in CVE-2023-7096?
CVE-2023-7096 describes a SQL injection vulnerability.
3
How do I fix CVE-2023-7096?
To fix CVE-2023-7096, sanitize and validate all user inputs, especially the 'fieldname' argument, to prevent SQL injection.
4
What functionality is affected by CVE-2023-7096?
CVE-2023-7096 affects an unknown functionality of the file /admin/php/crud.php.
5
Which software version is impacted by CVE-2023-7096?
CVE-2023-7096 impacts Faculty Management System version 1.0.