PT-2021-22932 · Paypal · Paypal

Published

2021-12-07

·

Updated

2021-12-16

·

CVE-2021-40578

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Enrollment Management System in PHP and PayPal Free Source Code version 1.0
Description The issue allows attackers to obtain sensitive information and execute arbitrary SQL commands via the IDNO parameter. This is an Authenticated Blind & Error-based SQL injection vulnerability.
Recommendations For Online Enrollment Management System in PHP and PayPal Free Source Code version 1.0, consider restricting access to the IDNO parameter to minimize the risk of exploitation. Avoid using the IDNO parameter in sensitive transactions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40578

Affected Products

Paypal