CVE-2021-41648
HIGHNuclei
PuneethReddyHC action.php SQL Injection
Record summary
CVE-2021-41648 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Proofs of concept
1Repository PoCs
GitHubMobiusBinary/CVE-2021-41648Repository PoCby MobiusBinaryStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHPuneethReddyHC action.php SQL InjectionCVSS 7.5
An unauthenticated SQL injection vulnerability exists in PuneethReddyHC Online Shopping through the /action.php prId parameter. Using a post request does not sanitize the user input.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
WeaknessesCWE-89
Authorsdaffainfo
Template tagscve2021cvesqlipacketstormonline-shopping-system-advanced_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:online-shopping-system-advanced_project:online-shopping-system-advanced:-:*:*:*:*:*:*:*
https://github.com/MobiusBinary/CVE-2021-41648 https://awesomeopensource.com/project/PuneethReddyHC/online-shopping-system https://nvd.nist.gov/vuln/detail/CVE-2021-41649 http://packetstormsecurity.com/files/165036/PuneethReddyHC-Online-Shopping-System-Advanced-1.0-SQL-Injection.html https://github.com/nu11secur1ty/Windows10Exploits
Source: ProjectDiscovery
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/165036/PuneethReddyHC-Online-Shopping-System-Advanced-1.0-SQL-Injection.html awesomeopensource.com
https://awesomeopensource.com/project/PuneethReddyHC/online-shopping-system github.com
https://github.com/MobiusBinary/CVE-2021-41648 github.com
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-41648 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-41648 nu11secur1ty.com
https://www.nu11secur1ty.com/2021/11/cve-2021-41648.html