SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.
References
| Link | Resource |
|---|---|
| https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204 | Exploit Third Party Advisory |
| https://momonguyen.com/2023/cve-2023-24203/ | URL Repurposed |
| https://www.sourcecodester.com | Product |
| https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204 | Exploit Third Party Advisory |
| https://momonguyen.com/2023/cve-2023-24203/ | URL Repurposed |
| https://www.sourcecodester.com | Product |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-05-14 17:15
Updated : 2025-04-23 16:33
NVD link : CVE-2023-24204
Mitre link : CVE-2023-24204
CVE.ORG link : CVE-2023-24204
JSON object : View
Products Affected
oretnom23
- simple_customer_relationship_management_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
