peter bassill · operator
$ cve CVE-2023-33584 JSON

CVE-2023-33584 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 14.2% (pctl 96)

Patch early

A public exploit exists.

Description

Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS14.24% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2023-06-21
Last modified2026-06-17

Affected (1)

VendorProduct
enrollment system projectenrollment system

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD