CVE-2021-40247

CRITICAL

Sourcecodester Budget and Expense Tracker System <v1 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.

Scores

CVSS v3 9.8
EPSS 0.0782
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
oretnom23/budget_and_expense_tracker_system 1.0
Published Jan 21, 2022
Tracked Since Feb 18, 2026