CVE-2021-36560

CRITICAL

Phone Shop Sales Managements System <1.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.

References (2)

Core 2
Core References
Product x_refsource_misc
https://www.sourcecodester.com/
Exploit, Third Party Advisory x_refsource_misc
https://pratikkhalane91.medium.com/cve-2021-35559-bb62022dd08a

Scores

CVSS v3 9.8
EPSS 0.0148
EPSS Percentile 70.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-425
Status published
Products (1)
phone_shop_sales_management_system_project/phone_shop_sales_management_system 1.0
Published Nov 02, 2021
Tracked Since Feb 18, 2026