cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-3693,https://securityvulnerability.io/vulnerability/CVE-2023-3693,SourceCodester Life Insurance Management System login.php sql injection,"A SQL injection vulnerability has been identified in the login.php file of SourceCodester's Life Insurance Management System 1.0. This flaw allows an attacker to manipulate the username argument, potentially leading to unauthorized access and manipulation of the database. Remote exploitation is possible, making systems using this application particularly vulnerable to attacks. Given that the exploit has been publicly disclosed, it is crucial for users to assess their security posture and apply necessary protections.",SourceCodester,Life Insurance Management System,9.8,CRITICAL,0.0021800000686198473,false,,false,false,false,,,false,false,,2023-07-16T22:15:00.000Z,0 CVE-2023-3165,https://securityvulnerability.io/vulnerability/CVE-2023-3165,SourceCodester Life Insurance Management System POST Parameter insertNominee.php cross site scripting,A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file insertNominee.php of the component POST Parameter Handler. The manipulation of the argument nominee_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231109 was assigned to this vulnerability.,Sourcecodester,Life Insurance Management System,3.5,LOW,0.0008800000068731606,false,,false,false,false,,,false,false,,2023-06-08T17:15:00.000Z,0