A vulnerability, which was classified as critical, was found in SourceCodester Gadget Works Online Ordering System 1.0. This affects an unknown part of the file /philosophy/admin/login.php of the component POST Parameter Handler. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222861 was assigned to this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23616 A vulnerability, which was classified as critical, was found in SourceCodester Gadget Works Online Ordering System 1.0. This affects an unknown part of the file /philosophy/admin/login.php of the component POST Parameter Handler. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222861 was assigned to this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-08-02T05:41:00.209Z

Reserved: 2023-03-12T07:13:51.308Z

Link: CVE-2023-1358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-03-12T08:15:10.170

Modified: 2024-11-21T07:39:01.397

Link: CVE-2023-1358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses