PT-2022-12027 · Sourcecodester · Sourcecodester Covid 19 Testing Management System

Published

2022-01-20

·

Updated

2022-01-26

·

CVE-2021-44245

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Courcecodester COVID 19 Testing Management System (CTMS) version 1.0
Description An SQL Injection issue exists via the username and contactno parameters.
Recommendations For Courcecodester COVID 19 Testing Management System (CTMS) version 1.0, consider restricting input for the username and contactno parameters to prevent SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44245

Affected Products

Sourcecodester Covid 19 Testing Management System