vendor:
Auto Dealer Management System
by:
Muhammad Navaid Zafar Ansari
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Auto Dealer Management System
Affected Version From: v 1.0
Affected Version To: v 1.0
Patch Exists: NO
Related CWE: CVE-2023-0913
CPE: a:sourcecodester:auto_dealer_management_system:1.0
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=50373, https://www.infosecmatter.com/nessus-plugin-library/?id=74336, https://www.infosecmatter.com/nessus-plugin-library/?id=68807, https://www.infosecmatter.com/nessus-plugin-library/?id=49758, https://www.infosecmatter.com/nessus-plugin-library/?id=68855, https://www.infosecmatter.com/nessus-plugin-library/?id=135464, https://www.infosecmatter.com/nessus-plugin-library/?id=121473, https://www.infosecmatter.com/nessus-plugin-library/?id=74478, https://www.infosecmatter.com/nessus-plugin-library/?id=74361, https://www.infosecmatter.com/nessus-plugin-library/?id=50605
Platforms Tested: Windows 11
2023
Auto Dealer Management System v1.0 – SQL Injection in sell_vehicle.php
The auto dealer management system supports two roles of users, one is admin, and another is a normal employee. The vulnerable page is sell_vehicle.php, which is accessible to both admin and employee users. This page is vulnerable to SQL Injection attack. The attacker can inject malicious SQL queries into the vulnerable parameter id and can access the database.
Mitigation:
To prevent SQL Injection attacks, developers should properly sanitize and validate all user input, and implement strong security measures, such as input validation, output encoding, parameterized queries, and access controls.