github.comexploit
https://github.com/tht1997/CVE_2023/blob/main/Lost%20and%20Found%20Information%20System/CVE-2023-2668.md CVE-2023-2668
MEDIUM
SourceCodester Lost and Found Information System GET Parameter manager_category sql injection
Record summary
CVE-2023-2668 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability was found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this issue is the function manager_category of the file admin/?page=categories/manage_category of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228884.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Lost and Found Information SystemBrowse SourceCodester / Lost and Found Information System | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2668 vuldb.comsignature
https://vuldb.com/?ctiid.228884 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.228884