CVE-2021-41511

CRITICAL

Lodging Reservation Management System - SQL Injection

Title source: rule

Description

The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.

Exploits (3)

exploitdb WORKING POC
by Nitin Sharma · textwebappsphp
https://www.exploit-db.com/exploits/50372
nomisec WORKING POC
by vidvansh · poc
https://github.com/vidvansh/CVE-2021-41511
inthewild WORKING POC
poc
https://github.com/ni7insharma/cve-2021-41511

Scores

CVSS v3 9.8
EPSS 0.0063
EPSS Percentile 70.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
lodging_reservation_management_system_project/lodging_reservation_management_system 1.0
Published Oct 04, 2021
Tracked Since Feb 18, 2026