CVE-2023-7106
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Feb 29, 2024
Updated: May 17, 2024
CWE ID 89
Summary
CVE-2023-7106 is a critical vulnerability identified in the code-projects E-Commerce Website 1.0. This issue affects an unnamed functionality in the file product_details.php?prod_id=11. The vulnerability enables an attacker to execute SQL injection through manipulation of the prod_id argument. The exploit can be launched remotely, and the vulnerability has been disclosed to the public, increasing the risk of exploitation. The Vulnerability Database has assigned the identifier VDB-249001 to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.