CVE-2021-43140
CRITICALSimple Subscription Website 1.0 - SQL Injection via Login
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-43140. PoCs published by Daniel Haro.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Simple Subscription Website 1.0, allowing authentication bypass via a crafted payload in the login request. The payload 'admin' or 1=1-- - bypasses authentication by manipulating the SQL query.
Description
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Simple Subscription Website 1.0, allowing authentication bypass via a crafted payload in the login request. The payload 'admin' or 1=1-- - bypasses authentication by manipulating the SQL query.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H