CVE-2023-33584 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 14.2% (pctl 96)
Patch early
A public exploit exists.
Description
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 14.24% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-06-21 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| enrollment system project | enrollment system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI) | 2023-06-04 |
References
- http://packetstormsecurity.com/files/172718/Enrollment-System-Project-1.0-Authentication-Bypass-SQL-Injection.html
- https://github.com/sudovivek/My-CVE/blob/main/CVE-2023-33584_exploit.md
- https://packetstormsecurity.com/files/cve/CVE-2023-33584
- https://www.exploit-db.com/exploits/51501
- https://www.sourcecodester.com/php/14444/enrollment-system-project-source-code-using-phpmysql.html
- http://packetstormsecurity.com/files/172718/Enrollment-System-Project-1.0-Authentication-Bypass-SQL-Injection.html
- https://github.com/sudovivek/My-CVE/blob/main/CVE-2023-33584_exploit.md
- https://packetstormsecurity.com/files/cve/CVE-2023-33584
- https://www.exploit-db.com/exploits/51501
- https://www.sourcecodester.com/php/14444/enrollment-system-project-source-code-using-phpmysql.html
→ the Explorer · watch your stack · NVD