github.comexploit
https://github.com/tht1997/CVE_2023/blob/main/Lost%20and%20Found%20Information%20System/CVE-2023-2672.md CVE-2023-2672
MEDIUM
SourceCodester Lost and Found Information System GET Parameter view.php sql injection
Record summary
CVE-2023-2672 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. Affected is an unknown function of the file items/view.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228888.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Lost and Found Information SystemBrowse SourceCodester / Lost and Found Information System | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2672 vuldb.comsignature
https://vuldb.com/?ctiid.228888 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.228888