8.8
CVSSv3

CVE-2023-38890

Published: 18/08/2023 Updated: 14/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Online Shopping Portal Project 3.1 allows remote malicious users to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgurukul online shopping portal 3.1

Github Repositories

poc

CVE-2023-38890 Description Online Shopping Portal Project V31 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks Exploit Title: Online Shopping