Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42169

Опубликовано: 22 окт. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:simple_payroll_system_with_dynamic_tax_bracket_project:simple_payroll_system_with_dynamic_tax_bracket:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00208
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.

EPSS

Процентиль: 43%
0.00208
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89