Required CVE Record Information
Description
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file templatedelete.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS 4 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.3 | MEDIUM | 4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
6.3 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
6.3 | MEDIUM | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
6.5 | — | 2.0 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
References 4 Total
- vuldb.com: VDB-294301 | itsourcecode Tailoring Management System templatedelete.php sql injection vdb-entrytechnical-description
- vuldb.com: VDB-294301 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- https://github.com/magic2353112890/cve/issues/7 exploitissue-tracking
- https://itsourcecode.com/ product