Record summary

CVE-2023-33584 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List1.0affected

Proofs of concept

2

Catalogued exploits

ExploitDBEnrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)ExploitDB exploitby VIVEK CHOUDHARYNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubsudovivek/Published-CVERepository PoCby sudovivekStars: 0Not analyzed3 files

3.5 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

7