Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.
https://github.com/ASR511-OO7/CVE-2023-33676/blob/main/CVE-30