Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-43130. PoCs published by Shafique_Wasta.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Customer Relationship Management System (CRM) 1.0. The payload '=' 'or' bypasses the login mechanism by manipulating the SQL query, allowing unauthorized access to the admin account.
Description
An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.
Exploits (1)
This exploit demonstrates an SQL injection authentication bypass in Customer Relationship Management System (CRM) 1.0. The payload '=' 'or' bypasses the login mechanism by manipulating the SQL query, allowing unauthorized access to the admin account.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H