First published: Fri Dec 29 2023(Updated: )
A vulnerability, which was classified as critical, was found in SourceCodester Free and Open Source Inventory Management System 1.0. This affects an unknown part of the file /ample/app/action/edit_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249177 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mayuri K Free And Open Source Inventory Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7155 is classified as a critical vulnerability.
CVE-2023-7155 allows for SQL injection through manipulation of the argument id in the edit_product.php file.
CVE-2023-7155 specifically affects SourceCodester Free and Open Source Inventory Management System version 1.0.
To mitigate CVE-2023-7155, validate and sanitize user inputs to prevent SQL injection attacks.
Exploiting CVE-2023-7155 could allow attackers to execute arbitrary SQL commands, potentially compromising the database.