Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-1955", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2023-04-08T06:29:45.793Z", "datePublished": "2023-04-08T10:00:06.587Z", "dateUpdated": "2024-08-02T06:05:27.069Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2024-02-13T07:52:19.773Z"}, "title": "SourceCodester Online Computer and Laptop Store User Registration login.php sql injection", "problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-89", "lang": "en", "description": "CWE-89 SQL Injection"}]}], "affected": [{"vendor": "SourceCodester", "product": "Online Computer and Laptop Store", "versions": [{"version": "1.0", "status": "affected"}], "modules": ["User Registration"]}], "descriptions": [{"lang": "en", "value": "A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is an unknown function of the file login.php of the component User Registration. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225342 is the identifier assigned to this vulnerability."}, {"lang": "de", "value": "Es wurde eine kritische Schwachstelle in SourceCodester Online Computer and Laptop Store 1.0 entdeckt. Es geht dabei um eine nicht klar definierte Funktion der Datei login.php der Komponente User Registration. Durch das Manipulieren des Arguments email mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."}], "metrics": [{"cvssV3_1": {"version": "3.1", "baseScore": 7.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseSeverity": "HIGH"}}, {"cvssV3_0": {"version": "3.0", "baseScore": 7.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "baseSeverity": "HIGH"}}, {"cvssV2_0": {"version": "2.0", "baseScore": 7.5, "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}}], "timeline": [{"time": "2023-04-08T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed"}, {"time": "2023-04-08T00:00:00.000Z", "lang": "en", "value": "CVE reserved"}, {"time": "2023-04-08T02:00:00.000Z", "lang": "en", "value": "VulDB entry created"}, {"time": "2023-04-26T09:30:03.000Z", "lang": "en", "value": "VulDB entry last update"}], "credits": [{"lang": "en", "value": "haicheng.zhang (VulDB User)", "type": "reporter"}], "references": [{"url": "https://vuldb.com/?id.225342", "tags": ["vdb-entry", "technical-description"]}, {"url": "https://vuldb.com/?ctiid.225342", "tags": ["signature", "permissions-required"]}, {"url": "https://github.com/boyi0508/Online-Computer-and-Laptop-Store/blob/main/User%20registration%20SQL%20injection.pdf", "tags": ["broken-link", "exploit"]}]}, "adp": [{"affected": [{"vendor": "online_computer_and_laptop_store_project", "product": "online_computer_and_laptop_store", "cpes": ["cpe:2.3:a:online_computer_and_laptop_store_project:online_computer_and_laptop_store:1.0:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "1.0", "status": "affected"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-07-18T18:19:52.742786Z", "id": "CVE-2023-1955", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-07-22T20:56:43.434Z"}}, {"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T06:05:27.069Z"}, "title": "CVE Program Container", "references": [{"url": "https://vuldb.com/?id.225342", "tags": ["vdb-entry", "technical-description", "x_transferred"]}, {"url": "https://vuldb.com/?ctiid.225342", "tags": ["signature", "permissions-required", "x_transferred"]}, {"url": "https://github.com/boyi0508/Online-Computer-and-Laptop-Store/blob/main/User%20registration%20SQL%20injection.pdf", "tags": ["broken-link", "exploit", "x_transferred"]}]}]}}