github.combroken linkexploit
https://github.com/TheCyberDiver/Public-Disclosures-CVE-/blob/main/Inventory%20Management%20System%20SQLi%20staff_data.md CVE-2023-4558
MEDIUM
SourceCodester Inventory Management System staff_data.php sql injection
Record summary
CVE-2023-4558 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file staff_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238159.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Inventory Management SystemBrowse SourceCodester / Inventory Management System | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-4558 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.238159 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.238159