CVE-2021-26201

CRITICAL

CASAP Automated Enrollment System 1.0 - SQL Injection Authentication Bypass via Login Username Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-26201. PoCs published by Himanshu Shukla.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in CASAP Automated Enrollment System 1.0 via SQL injection. It sends a crafted POST request with a malformed username to bypass authentication and gain admin access.

Description

The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.

Exploits (1)

exploitdb WORKING POC
by Himanshu Shukla · pythonwebappsphp
https://www.exploit-db.com/exploits/49463

This exploit demonstrates an authentication bypass vulnerability in CASAP Automated Enrollment System 1.0 via SQL injection. It sends a crafted POST request with a malformed username to bypass authentication and gain admin access.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: CASAP Automated Enrollment System 1.0
No auth needed
Prerequisites: Target URL with vulnerable login endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49463

Scores

CVSS v3 9.8
EPSS 0.0218
EPSS Percentile 80.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
casap_automated_enrollment_system_project/casap_automated_enrollment_system 1.0
Published Feb 15, 2021
Tracked Since Feb 18, 2026