CVE-2021-43510
Sourcecodester Simple Client Management System 1.0 - SQL Injection
Record summary
CVE-2021-43510 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALSourcecodester Simple Client Management System 1.0 - SQL InjectionCVSS 9.8
Sourcecodester Simple Client Management System 1.0 contains a SQL injection vulnerability via the username field in login.php. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the Sourcecodester Simple Client Management System 1.0.
Source: ProjectDiscovery