A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affects an unknown part of the file /bsms_ci/index.php/user/edit_user/. The manipulation of the argument password leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214587.
References
Link | Resource |
---|---|
https://github.com/lithonn/bug-report/tree/main/vendors/oretnom23/bsms_ci/passwd-hash | Exploit Third Party Advisory |
https://vuldb.com/?id.214587 | Third Party Advisory VDB Entry |
https://vuldb.com/?ctiid.214587 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-11-30 04:15
Updated : 2023-02-01 07:35
NVD link : CVE-2022-4228
Mitre link : CVE-2022-4228
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
book_store_management_system_project
- book_store_management_system