s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-1955

📛 CVE Title

SourceCodester Online Computer and Laptop Store User Registration login.php sql injection

Description

A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is an unknown function of the file login.php of the component User Registration. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225342 is the identifier assigned to this vulnerability.

Overview

State
PUBLISHED
Assigner (CNA)
VulDB
CVSS severity
HIGH
CVSS score
CVSS 7.3 / 10 7.3 7.3 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Effective score
7.3 / 10 HIGH source: CNA overview
CWE(s)
CWE-89
Reserved
2023-04-08
Published
2023-04-08 12:00 UTC
Last updated
2024-08-02 08:05 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/1xxx/CVE-2023-1955.json
Linked Threat
CVE-2023-1955 — SourceCodester Online Computer and Laptop Store User Registration login.php sql injection

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-24141
Assigner
VulDB
Published
Apr 8, 2023, 10:00:06 AM
Updated
Aug 2, 2024, 6:05:27 AM
EUVD base score (CVSS 3.1)
7.3 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EUVD-reported EPSS
0.3100
Vendors
SourceCodester
Products
Online Computer and Laptop Store (1.0)
Aliases
GHSA-qfxw-gf23-4xf5

ENISA description: A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is an unknown function of the file login.php of the component User Registration. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225342 is the identifier assigned to this vulnerability.

EUVD references (3)

Affected products (1)

VendorProductVersionsPlatforms
SourceCodester Online Computer and Laptop Store 1.0 (affected)

Vendor references (3)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
domain login.php no local data 2026-05-18 21:20 UTC

Flagged vendors

    Remediations (17)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.ibm.com

      IBM Support, Fix Central All code (including Machine Code updates, samples, fixes or other software downloads) provided on the Fix Central website is subject to the terms of the applicable license agreements. Machine Code updates for Power Systems and System Storage are available for IBM machines that are under warranty or an IBM hardware maintenance service agreement. Some exceptions apply ...

      2026-06-03 08:30 UTC
    • web:support.servicenow.com

      Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...

      2026-06-03 08:30 UTC
    • web:krebsonsecurity.com

      Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already ...

      2026-06-03 08:30 UTC
    • web:www.oracle.com

      Oracle Critical Patch Update Advisory - April 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

      2026-06-03 08:30 UTC
    • web:nvd.nist.gov

      The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...

      2026-06-03 08:30 UTC
    • web:www.rapid7.com

      Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.

      2026-06-03 08:30 UTC
    • web:access.redhat.com

      Learn about our open source products, services, and company. You are here

      2026-06-03 08:30 UTC
    • web:www.leagueoflegends.com

      League of Legends Patch 26.5 Notes Welcome to the official patch of First Stand, the first major international tournament of the year!

      2026-05-22 05:41 UTC
    • web:www.linkedin.com

      Microsoft Security Response Center has issued an emergency mitigation for a newly disclosed BitLocker bypass vulnerability known as "YellowKey," after security researchers publicly released ...

      2026-05-22 05:41 UTC
    • web:www.patchcareerinstitute.com

      P.A.T.C.H . Career Institute's mission is to provide quality training to students in the medical and vocational field. Our primary focus is to provide affordable, and competitive educational training for low to moderate income students.

      2026-05-22 05:41 UTC
    • web:www.sammobile.com

      Samsung has started rolling out the May 2026 security patch to the Galaxy A55, and the brand is offering it first in Europe.

      2026-05-22 05:41 UTC
    • web:epatch.pa.gov

      Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...

      2026-05-22 05:41 UTC
    • web:finance.yahoo.com

      Find the latest Comfort Systems USA, Inc. ( FIX ) stock quote, history, news and other vital information to help you with your stock trading and investing.

      2026-05-22 05:41 UTC
    • web:patch.moe

      Age Verification Are you 18 years or older? YES NO

      2026-05-22 05:41 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 05:41 UTC
    • web:www.cisa.gov

      Reboot WSUS server (s) after installation to complete mitigation . If organizations are unable to apply the update immediately, system administrators should disable the WSUS Server Role and/ or block inbound traffic to ports TCP 8530/TCP 8531, the default listeners for WSUS, at the host firewall.

      2026-05-22 05:41 UTC
    • web:www.fixtrading.org

      Learn more Standards and Guidelines FIX standards have driven electronic trading for 30 years and are constantly updated to support industry needs Learn more Events and Community Our member-driven global educational and networking events bring the industry together Learn more

      2026-05-22 05:41 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2023-1955.json.

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:online_computer_and_laptop_store_project:online_computer_and_laptop_store:1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "online_computer_and_laptop_store",
                "vendor": "online_computer_and_laptop_store_project",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-1955",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-18T18:19:52.742786Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-22T20:56:43.434Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T06:05:27.069Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "technical-description",
                  "x_transferred"
                ],
                "url": "https://vuldb.com/?id.225342"
              },
              {
                "tags": [
                  "signature",
                  "permissions-required",
                  "x_transferred"
                ],
                "url": "https://vuldb.com/?ctiid.225342"
              },
              {
                "tags": [
                  "broken-link",
                  "exploit",
                  "x_transferred"
                ],
                "url": "https://github.com/boyi0508/Online-Computer-and-Laptop-Store/blob/main/User%20registration%20SQL%20injection.pdf"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "User Registration"
              ],
              "product": "Online Computer and Laptop Store",
              "vendor": "SourceCodester",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "haicheng.zhang (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is an unknown function of the file login.php of the component User Registration. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225342 is the identifier assigned to this vulnerability."
            },
            {
              "lang": "de",
              "value": "Es wurde eine kritische Schwachstelle in SourceCodester Online Computer and Laptop Store 1.0 entdeckt. Es geht dabei um eine nicht klar definierte Funktion der Datei login.php der Komponente User Registration. Durch das Manipulieren des Arguments email mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-13T07:52:19.773Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.225342"
            },
            {
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.225342"
            },
            {
              "tags": [
                "broken-link",
                "exploit"
              ],
              "url": "https://github.com/boyi0508/Online-Computer-and-Laptop-Store/blob/main/User%20registration%20SQL%20injection.pdf"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2023-04-08T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2023-04-08T00:00:00.000Z",
              "value": "CVE reserved"
            },
            {
              "lang": "en",
              "time": "2023-04-08T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2023-04-26T09:30:03.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "SourceCodester Online Computer and Laptop Store User Registration login.php sql injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2023-1955",
        "datePublished": "2023-04-08T10:00:06.587Z",
        "dateReserved": "2023-04-08T06:29:45.793Z",
        "dateUpdated": "2024-08-02T06:05:27.069Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }