CVE-2023-4556

A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by this issue is the function mysqli_query of the file sexit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-238154 is the identifier assigned to this vulnerability.
References
Link Resource
https://blog.csdn.net/weixin_43864034/article/details/132508000 Exploit Third Party Advisory
https://vuldb.com/?ctiid.238154 Permissions Required Third Party Advisory
https://vuldb.com/?id.238154 Third Party Advisory
https://blog.csdn.net/weixin_43864034/article/details/132508000 Exploit Third Party Advisory
https://vuldb.com/?ctiid.238154 Permissions Required Third Party Advisory
https://vuldb.com/?id.238154 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:online_graduate_tracer_system_project:online_graduate_tracer_system:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:35

Type Values Removed Values Added
CVSS v2 : 6.5
v3 : 9.8
v2 : 6.5
v3 : 6.3
References () https://blog.csdn.net/weixin_43864034/article/details/132508000 - Exploit, Third Party Advisory () https://blog.csdn.net/weixin_43864034/article/details/132508000 - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.238154 - Permissions Required, Third Party Advisory () https://vuldb.com/?ctiid.238154 - Permissions Required, Third Party Advisory
References () https://vuldb.com/?id.238154 - Third Party Advisory () https://vuldb.com/?id.238154 - Third Party Advisory

29 Aug 2023, 05:02

Type Values Removed Values Added
CPE cpe:2.3:a:online_graduate_tracer_system_project:online_graduate_tracer_system:1.0:*:*:*:*:*:*:*
References (MISC) https://vuldb.com/?id.238154 - (MISC) https://vuldb.com/?id.238154 - Third Party Advisory
References (MISC) https://vuldb.com/?ctiid.238154 - (MISC) https://vuldb.com/?ctiid.238154 - Permissions Required, Third Party Advisory
References (MISC) https://blog.csdn.net/weixin_43864034/article/details/132508000 - (MISC) https://blog.csdn.net/weixin_43864034/article/details/132508000 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Online Graduate Tracer System Project online Graduate Tracer System
Online Graduate Tracer System Project

27 Aug 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-27 07:15

Updated : 2024-11-21 08:35


NVD link : CVE-2023-4556

Mitre link : CVE-2023-4556

CVE.ORG link : CVE-2023-4556


JSON object : View

Products Affected

online_graduate_tracer_system_project

  • online_graduate_tracer_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')