CVE-2021-43420

CRITICAL

Sourcecodester Online Payment Hub - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

Scores

CVSS v3 9.8
EPSS 0.0026
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
online_payment_hub_project/online_payment_hub 1.0
Published Jan 24, 2022
Tracked Since Feb 18, 2026