CVE-2021-36621
HIGHOnline Covid Vaccination Scheduler System - SQL Injection
Title source: ruleDescription
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.
Exploits (1)
References (3)
Scores
CVSS v3
8.1
EPSS
0.0131
EPSS Percentile
79.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
online_covid_vaccination_scheduler_system_project/online_covid_vaccination_scheduler_system
1.0
Published
Jul 30, 2021
Tracked Since
Feb 18, 2026