PT-2021-23509 · Unknown · Phpeventcalendar
Erik Steltzner
+1
·
Published
2021-11-05
·
Updated
2021-11-09
·
CVE-2021-42077
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PHP Event Calendar versions prior to 2021-09-03
Description
The issue allows SQL injection, as demonstrated by the "/server/ajax/user manager.php" endpoint, specifically the
username parameter. This can be used to execute SQL statements directly on the database, potentially allowing an adversary to compromise the database system or bypass the login form.Recommendations
For versions prior to 2021-09-03, update to a version released after 2021-09-03 to resolve the issue. As a temporary workaround, consider restricting access to the "/server/ajax/user manager.php" endpoint or sanitizing the
username parameter to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpeventcalendar