CVE-2021-46075

HIGH

Sourcecodester Vehicle Service Mgmt 1.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2021-46075. PoCs published by sanupl, plsanu.

AI-analyzed exploit summary The repository provides a detailed technical analysis of CVE-2021-46075, a privilege escalation vulnerability in Sourcecodester Vehicle Service Management System 1.0. It describes how staff accounts can access admin resources and perform CRUD operations by directly navigating to restricted URLs.

Description

A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.

Exploits (3)

nomisec WRITEUP 1 stars
by sanupl · poc
https://github.com/sanupl/CVE-2021-46075

The repository provides a detailed technical analysis of CVE-2021-46075, a privilege escalation vulnerability in Sourcecodester Vehicle Service Management System 1.0. It describes how staff accounts can access admin resources and perform CRUD operations by directly navigating to restricted URLs.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Vehicle Service Management System 1.0
Auth required
Prerequisites: Access to a staff account · Admin panel URL
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WRITEUP
by sanupl · poc
https://github.com/sanupl/Vehicle-Service-Management-System-Multiple-Privilege-Escalation-Leads-to-CRUD-Operations

This repository provides a detailed technical analysis of CVE-2021-46075, a privilege escalation vulnerability in Sourcecodester Vehicle Service Management System 1.0. It describes how staff accounts can access admin resources and perform CRUD operations by directly navigating to restricted URLs.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Vehicle Service Management System 1.0
Auth required
Prerequisites: Valid staff account credentials · Access to the admin panel URL
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WRITEUP
by plsanu · poc
https://github.com/plsanu/Vehicle-Service-Management-System-Multiple-Privilege-Escalation-Leads-to-CRUD-Operations

This repository contains a detailed writeup describing multiple privilege escalation vulnerabilities in Sourcecodester Vehicle Service Management System 1.0, allowing staff accounts to access admin resources and perform CRUD operations.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Vehicle Service Management System 1.0
Auth required
Prerequisites: Access to a staff account · Admin panel URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.2
EPSS 0.0262
EPSS Percentile 83.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (1)
vehicle_service_management_system_project/vehicle_service_management_system < 1.0
Published Jan 06, 2022
Tracked Since Feb 18, 2026