PT-2021-3761 · Sourcecodester · Sourcecodester Casap Automated Enrollment System

Published

2021-01-25

·

Updated

2021-07-30

·

CVE-2021-26223

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SourceCodester CASAP Automated Enrollment System version 1.0
Description The issue is related to a lack of protection for the SQL query structure, allowing remote attackers to execute arbitrary SQL statements. This can impact the confidentiality, integrity, and availability of protected information through the id parameter in "view pay.php".
Recommendations For SourceCodester CASAP Automated Enrollment System version 1.0, consider restricting access to the "view pay.php" endpoint to minimize the risk of exploitation, and avoid using the id parameter until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04016
CVE-2021-26223

Affected Products

Sourcecodester Casap Automated Enrollment System