CVE-2023-7331 Details
Description
A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerability affects unknown code of the component User Handler. Performing manipulation results in sql injection. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 25c9965a872c704f3a9475488dc5d3196902199a. It is suggested to install a patch to address this issue.
A SQL injection vulnerability has been identified in PKrystian Full-Stack-Bank versions prior to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. The issue arises in the User Handler component, where improper handling of user input allows for SQL injection attacks. This vulnerability can be exploited remotely and requires authentication.
Users are advised to update to the latest version of PKrystian Full-Stack-Bank, where this vulnerability has been addressed. The patch is available on the project's GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 31, 2025CISA-ADP
Assessed Jan 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/PKrystian/Full-Stack-Bank/commit/25c9965a872c704f3a9475488dc5d3196902199a | [email protected] | Source CodeVendor |
| https://github.com/PKrystian/Full-Stack-Bank/pull/21 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/?ctiid.338650 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.338650 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PKrystian Full-Stack-Bank | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 31, 2025 | New CVE Received | [email protected] |
Volerion