NA

CVE-2023-46582

Published: 14/11/2023 Updated: 20/11/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

SQL injection vulnerability in Inventory Management v.1.0 allows a local malicious user to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component.

Vulnerable Product Search on Vulmon Subscribe to Product

code-projects inventory management 1.0

Github Repositories

Code-Projects Inventory Management 10 Welcome to the Code-Projects Inventory Management 10 repository This project aims to provide efficient inventory management Security Vulnerabilities CVE-2023-46580 Description: Stored Cross-Site Scripting (XSS) vulnerability via editProductphp, 'pname' parameter Affected Version: 10 Affected File: /Inventory-Management/mod