CVE-2021-44567
CRITICALRosarioSIS < 7.6.1 - Unauthenticated SQL Injection via PortalPollsNotes Votes Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-44567. PoCs published by CodeSecLab.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in RosarioSIS 7.6 via the PortalPollsNotes.fnc.php endpoint. The PoC shows how an attacker can inject malicious SQL payloads through the 'votes' POST parameter to execute arbitrary SQL commands, such as creating a new table.
Description
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in RosarioSIS 7.6 via the PortalPollsNotes.fnc.php endpoint. The PoC shows how an attacker can inject malicious SQL payloads through the 'votes' POST parameter to execute arbitrary SQL commands, such as creating a new table.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H