1 results (0.002 seconds)
CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1
CVE-2023-3004 – SourceCodester Simple Chat System POST Parameter sql injection
https://notcve.org/view.php?id=CVE-2023-3004
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Chat System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=read_msg of the component POST Parameter Handler. The manipulation of the argument convo_id leads to sql injection. The attack may be launched remotely. • https://github.com/sikii7/CVE/blob/main/SQL.md https://vuldb.com/?ctiid.230348 https://vuldb.com/?id.230348 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •