PT-2022-11208 · Unknown · Sourcecodester Budget/Expense Tracker System

Oretnom23

·

Published

2022-01-21

·

Updated

2024-02-03

·

CVE-2021-40247

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Budget and Expense Tracker System version v1
Description The issue allows attackers to execute arbitrary SQL commands via the username field, potentially leading to unauthorized data access or modification. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Sourcecodester Budget and Expense Tracker System version v1, consider restricting access to the username field to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-40247

Affected Products

Sourcecodester Budget/Expense Tracker System