CVE-2021-44600SQL Injection in Simple Online MEN S Salon Management System

CWE-89SQL Injection3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 47.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateDec 24

Description

The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve all authentication and information about the users of this system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-h9pf-hjmx-3mpq: The password parameter on Simple Online Mens Salon Management System (MSMS) 12021-12-24
CVEList
CVE-2021-44600: The password parameter on Simple Online Mens Salon Management System (MSMS) 12021-12-23
CVE-2021-44600 — SQL Injection | cvebase