CVE-2021-36560

CRITICAL

Phone Shop Sales Managements System <1.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.

Scores

CVSS v3 9.8
EPSS 0.0046
EPSS Percentile 64.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-425
Status published
Products (1)
phone_shop_sales_management_system_project/phone_shop_sales_management_system 1.0
Published Nov 02, 2021
Tracked Since Feb 18, 2026