CVE-2023-6464: SourceCodester User Registration and Login System add-user.php sql injection
A vulnerability was found in SourceCodester User Registration and Login System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument user leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-246614 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-6464.
What is the severity level of CVE-2023-6464?
The severity level of CVE-2023-6464 is critical.
What is affected by CVE-2023-6464?
The SourceCodester User Registration and Login System version 1.0 is affected by CVE-2023-6464.
How can an attacker exploit CVE-2023-6464?
An attacker can exploit CVE-2023-6464 by manipulating the 'user' argument to perform SQL injection.
Are there any references for CVE-2023-6464?
Yes, here are some references for CVE-2023-6464: [Link 1](https://vuldb.com/?id.246614), [Link 2](https://vuldb.com/?ctiid.246614), [Link 3](https://github.com/qqisee/vulndis/blob/main/sqlInjection_delete_user.md).