First published: Mon Dec 25 2023(Updated: )
A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user_signup.php. The manipulation of the argument firstname/middlename/email/address/contact/username leads to sql injection. The attack may be launched remotely. VDB-249002 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fabianros E-commerce Website | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7107 has been rated as critical due to SQL injection vulnerabilities.
To fix CVE-2023-7107, validate and sanitize user inputs in the user_signup.php file.
CVE-2023-7107 affects the user_signup.php file in the E-Commerce Website version 1.0.
CVE-2023-7107 allows for SQL injection through the manipulation of the firstname, middlename, email, address, contact, and username parameters.
CVE-2023-7107 specifically impacts version 1.0 of Fabianros E-commerce Website and may not be present in other versions.