PT-2021-3845 · Sourcecodester · Sourcecodester E-Commerce Website

Bigtiger2020

·

Published

2021-01-14

·

Updated

2021-07-29

·

CVE-2021-25205

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester E-Commerce Website version 1.0
Description The issue allows remote attackers to execute arbitrary SQL statements via the update parameter to "empViewUpdate.php". This is related to the lack of protection for the SQL query structure, which can enable an attacker to conduct cross-site scripting attacks.
Recommendations For version 1.0, consider disabling access to the "empViewUpdate.php" script until a patch is available, or restrict the use of the update parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04200
CVE-2021-25205

Affected Products

Sourcecodester E-Commerce Website