PT-2022-11456 · Unknown · Sourcecodester Banking System

Published

2022-01-24

·

Updated

2025-12-16

·

CVE-2021-41659

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Banking System version 1
Description The issue allows attackers to execute arbitrary SQL commands via the username or password field, potentially leading to unauthorized access or data manipulation.
Recommendations For Sourcecodester Banking System version 1, consider restricting access to the login functionality until a patch is available, and avoid using the username and password fields in a way that could facilitate SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-41659

Affected Products

Sourcecodester Banking System