CVE-2023-5580 – SourceCodester Library System index.php sql injection
https://notcve.org/view.php?id=CVE-2023-5580
A vulnerability classified as critical has been found in SourceCodester Library System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/GodRone/CVE/blob/main/SerBermz_SQL%20injection.md https://vuldb.com/?ctiid.242145 https://vuldb.com/?id.242145 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-26200
https://notcve.org/view.php?id=CVE-2021-26200
The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user. El área de usuario de Library System versión 1.0, es vulnerable a la inyección SQL, donde un usuario puede omitir la autenticación e iniciar sesión como usuario administrador • https://www.exploit-db.com/exploits/49462 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •