SourceCodester Sanitization Management System sql injection
Description
A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affects some unknown processing of the file /php-sms/?p=services/view_service. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210839.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in SourceCodester Sanitization Management System via id parameter in view_service allows remote attackers to execute arbitrary SQL queries.
Vulnerability
A critical SQL injection vulnerability exists in SourceCodester Sanitization Management System (version unspecified) in the file /php-sms/?p=services/view_service. The id parameter is not properly sanitized before being used in a SQL query, allowing an attacker to inject arbitrary SQL commands. The vulnerability is classified as critical and has been publicly disclosed [1].
Exploitation
An attacker can exploit this vulnerability remotely without authentication by sending a crafted HTTP request to the vulnerable endpoint with a malicious id parameter. The exploit has been demonstrated and is publicly available, as shown in the referenced proof-of-concept image [1]. No special privileges or user interaction are required.
Impact
Successful exploitation allows an attacker to execute arbitrary SQL statements on the backend database. This can lead to unauthorized access to sensitive data, modification or deletion of database records, and potentially further compromise of the server depending on database permissions.
Mitigation
As of the publication date (2022-10-14), no official patch or fixed version has been released by SourceCodester. Users should consider restricting network access to the application, implementing a web application firewall (WAF) to block SQL injection attempts, or migrating to an alternative solution if available. The vendor has not provided a workaround.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- SourceCodester/Sanitization Management Systemv5Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.