Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-58276 1 Enrollment System Project 1 Enrollment System 2026-08-14 N/A
Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.
CVE-2023-33584 1 Enrollment System Project 1 Enrollment System 2024-11-21 9.8 Critical
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.