Vulnerability CVE-2023-1441


Published: 2023-03-17

Description:
A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/courses/view_course.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223285 was assigned to this vulnerability.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://vuldb.com/?id.223285
https://github.com/SecurityYH/bug_report/blob/main/SQLi-1.md
https://vuldb.com/?ctiid.223285

Copyright 2023, cxsecurity.com

 

Back to Top