CVE-2021-43130

CRITICAL

Sourcecodester CRM 1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-43130. PoCs published by Shafique_Wasta.

AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Customer Relationship Management System (CRM) 1.0. The payload '=' 'or' bypasses the login mechanism by manipulating the SQL query, allowing unauthorized access to the admin account.

Description

An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.

Exploits (1)

exploitdb WORKING POC
by Shafique_Wasta · textwebappsphp
https://www.exploit-db.com/exploits/50158

This exploit demonstrates an SQL injection authentication bypass in Customer Relationship Management System (CRM) 1.0. The payload '=' 'or' bypasses the login mechanism by manipulating the SQL query, allowing unauthorized access to the admin account.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Customer Relationship Management System (CRM) 1.0
No auth needed
Prerequisites: Access to the login page at http://localhost/crm/customer/login.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50158
Exploit, Third Party Advisory x_refsource_misc
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-43130

Scores

CVSS v3 9.8
EPSS 0.0222
EPSS Percentile 80.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
customer_relationship_management_system_project/customer_relationship_management_system 1.0
Published Nov 03, 2021
Tracked Since Feb 18, 2026