github.com
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-38840 CVE-2021-38840
CRITICAL
Simple Water Refilling Station Management System 1.0 - Authentication Bypass
Record summary
CVE-2021-38840 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits.
Description
SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBSimple Water Refilling Station Management System 1.0 - Authentication BypassExploitDB exploitby Matt SorrellNot analyzed1 file
ExploitDBSimple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File UploadExploitDB exploitby Matt SorrellNot analyzed1 file
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-38840 exploit-db.com
https://www.exploit-db.com/exploits/50204 exploit-db.com
https://www.exploit-db.com/exploits/50205 sourcecodester.com
https://www.sourcecodester.com/php/14906/simple-water-refilling-station-management-system-php-free-source-code.html sourcecodester.com
https://www.sourcecodester.com/users/tips23