CVE-2023-2215

MEDIUM EXPLOITED

Coffee Shop Pos System - SQL Injection

Title source: rule

Description

A vulnerability classified as critical has been found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226980.

Exploits (1)

nomisec WORKING POC 4 stars
by zwxxb · remote
https://github.com/zwxxb/CVE-2023-2215

Scores

CVSS v3 6.3
EPSS 0.0411
EPSS Percentile 88.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

VulnCheck KEV 2024-06-26
CWE
CWE-89
Status published
Products (1)
coffee_shop_pos_system_project/coffee_shop_pos_system 1.0
Published Apr 21, 2023
Tracked Since Feb 18, 2026