PT-2021-24138 · Unknown · Online Enrollment Management System

Published

2021-12-23

·

Updated

2022-01-04

·

CVE-2021-44599

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Online Enrollment Management System version 1.0
Description: The issue allows for SQL injection attacks through the id parameter. An attacker can craft a payload that injects a SQL sub-query, utilizing MySQL's load file function with a UNC file path referencing a URL on an external domain. This results in the application interacting with the external domain, indicating successful execution of the injected SQL query. The attacker can retrieve sensitive information for all users of the system.
Recommendations: For Online Enrollment Management System version 1.0, consider restricting access to the id parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the id parameter in sensitive operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44599

Affected Products

Online Enrollment Management System