CVE-2023-4200 is a critical SQL injection vulnerability affecting SourceCodester Inventory Management System 1.0, specifically within the product_data.php file through manipulation of the columns[1][data] argument. With a CVSS score of 9.8 (CRITICAL), it is remotely exploitable with low attack complexity, allowing for complete compromise of confidentiality, integrity, and availability. While public exploit details exist, there are no known Metasploit or Nuclei modules, and it currently lacks significant community discussion or media coverage, suggesting limited active exploitation despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:mayurik:inventory_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.