CVE-2021-26201
CRITICALCASAP Automated Enrollment System 1.0 - SQL Injection Authentication Bypass via Login Username Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-26201. PoCs published by Himanshu Shukla.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in CASAP Automated Enrollment System 1.0 via SQL injection. It sends a crafted POST request with a malformed username to bypass authentication and gain admin access.
Description
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in CASAP Automated Enrollment System 1.0 via SQL injection. It sends a crafted POST request with a malformed username to bypass authentication and gain admin access.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H