PT-2021-21874 · Sourcecodester · Sourcecodester Online Covid Vaccination Scheduler System

Published

2021-10-27

·

Updated

2021-11-02

·

CVE-2021-37803

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sourcecodester Online Covid Vaccination Scheduler System version 1.0
Description: An SQL Injection issue exists via the username in lognin.php.
Recommendations: For Sourcecodester Online Covid Vaccination Scheduler System version 1.0, consider restricting access to the lognin.php file until a patch is available. As a temporary workaround, avoid using the username variable in the affected login functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37803

Affected Products

Sourcecodester Online Covid Vaccination Scheduler System