PT-2021-23509 · Unknown · Phpeventcalendar

Erik Steltzner

+1

·

Published

2021-11-05

·

Updated

2021-11-09

·

CVE-2021-42077

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP Event Calendar versions prior to 2021-09-03
Description The issue allows SQL injection, as demonstrated by the "/server/ajax/user manager.php" endpoint, specifically the username parameter. This can be used to execute SQL statements directly on the database, potentially allowing an adversary to compromise the database system or bypass the login form.
Recommendations For versions prior to 2021-09-03, update to a version released after 2021-09-03 to resolve the issue. As a temporary workaround, consider restricting access to the "/server/ajax/user manager.php" endpoint or sanitizing the username parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42077

Affected Products

Phpeventcalendar