Record summary

CVE-2021-3239 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBE-Learning System 1.0 - Authentication BypassExploitDB exploitby Himanshu ShuklaNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALE-Learning System 1.0 - SQL InjectionCVSS 9.8

E-Learning System 1.0 contains an unauthenticated SQL injection caused by unsanitized input, letting remote attackers execute arbitrary code on the server and gain a reverse shell, exploit requires no authentication.

Impact

Attackers can execute arbitrary code on the server, leading to full system compromise and remote control.

Remediation

Apply input validation and parameterized queries, update to the latest version if available.

WeaknessesCWE-89
Authorsxuxeong
Template tagscvecve2021sqlielearningvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: http.title:"E-Learning System"
FOFA: title="E-Learning System"

Source: ProjectDiscovery

References

6