First published: Thu Dec 28 2023(Updated: )
A vulnerability, which was classified as critical, was found in code-projects Client Details System 1.0. This affects an unknown part of the file /admin of the component HTTP POST Request Handler. The manipulation of the argument username leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249141 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7138 is classified as a critical vulnerability.
To fix CVE-2023-7138, ensure that you sanitize and validate all user inputs for the username parameter to prevent SQL injection.
CVE-2023-7138 affects the HTTP POST Request Handler within the /admin directory of the Client Details System 1.0.
CVE-2023-7138 is an SQL injection vulnerability that exploits the manipulation of the username argument.
CVE-2023-7138 impacts version 1.0 of the Client Details System.