CVE-2021-42665 — SQL Injection in Online Portal Project Engineers Online Portal
Severity
9.8CRITICALNVD
EPSS
5.0%
top 10.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 5
Latest updateMay 24
Description
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-5vc7-wq49-64h9: An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index↗2022-05-24
CVEList▶
CVE-2021-42665: An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index↗2021-11-05