PT-2021-23651 · Unknown · Sourcecodester Engineers Online Portal

Nu11Secur1Ty

·

Published

2021-11-05

·

Updated

2021-11-17

·

CVE-2021-42670

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sourcecodester Engineers Online Portal (affected versions not specified)
Description A SQL injection issue exists via the id parameter to the "announcements student.php" web page, allowing a malicious user to extract sensitive data from the web server. In some cases, this issue can be used to achieve remote code execution on the remote web server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42670

Affected Products

Sourcecodester Engineers Online Portal