Back to Labs
Security Advisory

CVE-2023-3457

About

A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-232674 is the identifier assigned to this vulnerability.

Weakness (CWE):CWE-89

Rainforest analyst review

SourceCodester Shopping Website 1.0 takes the username argument to index.php and feeds it into a SQL query without neutralizing it, so a crafted username rewrites the query logic. Sitting on the login and index path, that typically means authentication bypass or dumping the user and order tables. A public exploit (VDB-232674) is already circulating, so the injection point is confirmed and reachable.

The proportionate read is that this is small demonstration-grade e-commerce software with a thin real-world install base, not a widely deployed platform. Published PoCs against apps like this feed opportunistic scanning more than coordinated campaigns; the danger is a low-effort attacker landing on one of the few live instances. The vector needs only low privileges, and against a login-adjacent parameter that bar is effectively floor-level.

We rank this by whether it's actually in our estate rather than by the fact that an exploit exists. Our inventory pass looks for SourceCodester-derived shopping code on any exposed host; where nothing turns up, a public PoC is irrelevant. Where something does, we treat a login-path injection as a credential-and-data exposure and prioritize taking it off the public internet over patching software that may be unmaintained.

References

Related CVEs

Frequently asked questions

What is CVE-2023-3457?

A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-232674 is the identifier assigned to this vulnerability.

How severe is CVE-2023-3457?

CVE-2023-3457 carries a CVSS 3.1 base score of 6.3, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 67 out of 100, in the elevated band.

How is CVE-2023-3457 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality Low, integrity Low and availability Low.

Which products are affected by CVE-2023-3457?

Public advisories list the following as affected: shopping website. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-3457?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email