CVE-2021-41511
CRITICALLodging Reservation Management System 1.0 - SQL Injection via Login Username/Password Fields
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2021-41511. PoCs published by Nitin Sharma, vidvansh.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Lodging Reservation Management System 1.0 via SQL injection. By manipulating the username and password fields with SQL payloads, an attacker can bypass authentication and gain admin access.
Description
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
Exploits (3)
This exploit demonstrates an authentication bypass vulnerability in Lodging Reservation Management System 1.0 via SQL injection. By manipulating the username and password fields with SQL payloads, an attacker can bypass authentication and gain admin access.
This PoC demonstrates an SQL injection vulnerability in Lodging Reservation Management System 1.0, allowing authentication bypass via crafted username and password inputs. The exploit uses a classic SQLi payload to bypass login checks.
This repository provides a functional SQL injection exploit for CVE-2021-41511, demonstrating an authentication bypass in Lodging Reservation Management System 1.0 via crafted username/password inputs. The PoC includes a Burp Suite-captured HTTP request with the payload ' or 1 -- -.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H