CVE-2023-1735 is a critical SQL injection vulnerability found in SourceCodester Young Entrepreneur E-Negosyo System 1.0, specifically within the passwordrecover.php file when handling the 'phonenumber' argument. This flaw allows for remote exploitation with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. While no public exploit code (Metasploit, Nuclei, ExploitDB) or active exploitation is currently reported, and community discussion is minimal, organizations using the affected system should prioritize patching due to the severe potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:young_entrepreneur_e-negosyo_system_project:young_entrepreneur_e-negosyo_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.