CVE-2023-33592 | SourceCodester Lost and Found Information System 1.0 contact_information sql injection (ID 173331 / EUVD-2023-37748)
A vulnerability labeled as critical has been found in SourceCodester Lost and Found Information System 1.0. The affected element is an unknown function of the file /php-lfis/admin/?page=system_info/contact_information. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2023-33592. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.