← Back to browse · API

CVE-2023-33584

Severity
CRITICAL
CVSS
9.8
EPSS
0.14242
Risk score
44.18
CISA KEV
No
PoC
No
Published
2023-06-21
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2023-37740, GHSA-8WQH-3WXX-4342
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-37740

Description

Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.

References