Author: Angelo Barbosa

CVE-2023-6312 | SourceCodester Loan Management System 1.0 Users Page deleteUser.php delete_user user_id sql injection

A vulnerability was found in SourceCodester Loan Management System 1.0. It has been classified as critical. Affected is the function delete_user of the file deleteUser.php of the component Users Page. The manipulation of the argument user_id leads to sql injection. This vulnerability is traded as CVE-2023-6312. It is possible to launch the attack remotely. Furthermore, there is an exploit...

Read More

CVE-2023-6311 | SourceCodester Loan Management System 1.0 Loan Type Page delete_ltype.php delete_ltype ltype_id sql injection

A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects the function delete_ltype of the file delete_ltype.php of the component Loan Type Page. The manipulation of the argument ltype_id leads to sql injection. The identification of this vulnerability is CVE-2023-6311. The attack may be initiated remotely. Furthermore, there is an exploit...

Read More

CVE-2023-6310 | SourceCodester Loan Management System 1.0 deleteBorrower.php delete_borrower borrower_id sql injection

A vulnerability has been found in SourceCodester Loan Management System 1.0 and classified as critical. This vulnerability affects the function delete_borrower of the file deleteBorrower.php. The manipulation of the argument borrower_id leads to sql injection. This vulnerability was named CVE-2023-6310. The attack can be initiated remotely. Furthermore, there is an exploit...

Read More

CVE-2023-6309 | moses-smt mosesdecoder up to 4.0 trans_result.php input1 os command injection

A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iSenWeb/trans_result.php. The manipulation of the argument input1 leads to os command injection. This vulnerability is uniquely identified as CVE-2023-6309. The attack can only be done within the local network. Furthermore, there is an exploit...

Read More

CVE-2023-6308 | Xiamen Four-Faith Video Surveillance Management System 2016/2017 Apache Struts unrestricted upload

A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by this issue is some unknown functionality of the component Apache Struts. The manipulation leads to unrestricted upload. This vulnerability is handled as CVE-2023-6308. The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Read More