PT-2021-23558 · Sqlite Consortium+2 · Sqlite+2

Oretnom23

·

Published

2021-10-22

·

Updated

2023-09-28

·

CVE-2021-42169

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite (affected versions not specified)
Description The issue concerns a remote SQL injection bypass authentication vulnerability for the admin account. The username parameter from the login form is not properly protected, allowing malicious payloads to bypass security measures.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-42169

Affected Products

Php
Sqlite
Simple Payroll System