CVE-2023-3878
Campcodes Beauty Salon Management System about-us.php sql injection
Description
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235240.
In plain language
AI Worth attentionBeauty Salon Management System 1.0 has a database-input flaw in its admin area, so businesses using it should restrict access and seek vendor guidance.
Authenticated remote SQL injection in Campcodes Beauty Salon Management System 1.0 via the pagedes parameter in /admin/about-us.php permits limited confidentiality, integrity, and availability impact.
What to do now
- Confirm whether you run Beauty Salon Management System 1.0 and whether its admin area includes the About Us page.
- Limit admin-area access to trusted staff and networks, and remove inactive administrator accounts.
- No fixed version is currently available; ask the vendor for a security update or supported replacement.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2023-3878 and every CVE in our database. Create a free account — no credit card required.
Create Free Account