CVE-2023-0904
MEDIUMSourceCodester Employee Task Management System 1.0 - SQL Injection via task_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0904. PoCs published by Muhammad Navaid Zafar Ansari.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Employee Task Management System v1.0 via the 'task_id' parameter in 'task-details.php'. The PoC includes a crafted HTTP request that extracts database version, name, and user information.
Description
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221453 was assigned to this vulnerability.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Employee Task Management System v1.0 via the 'task_id' parameter in 'task-details.php'. The PoC includes a crafted HTTP request that extracts database version, name, and user information.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L