PT-2021-20389 · Unknown · Sourcecodester Simple Forum Website

Published

2021-07-28

·

Updated

2022-05-03

·

CVE-2021-34166

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Sourcecodester Simple Food Website version 1.0
Description: A SQL injection issue allows a remote attacker to bypass authentication and gain administrative access.
Recommendations: For Sourcecodester Simple Food Website version 1.0, update the software to a version that fixes the SQL injection issue, or as a temporary workaround, consider restricting access to sensitive areas of the website to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34166

Affected Products

Sourcecodester Simple Forum Website