github.com
https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/CVE-nu11-21-100521 CVE-2021-42169
CRITICAL
Simple Payroll System 1.0 - SQLi Authentication Bypass
Record summary
CVE-2021-42169 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSimple Payroll System 1.0 - SQLi Authentication BypassExploitDB exploitby Yash MahajanNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-42169 exploit-db.com
https://www.exploit-db.com/exploits/50403