nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47777 CVE-2021-47777
HIGH
Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
Record summary
CVE-2021-47777 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Build Smart ERPBrowse Ribccs / Build Smart ERP | CVE List | 21.0817 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBBuild Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)ExploitDB exploitby Nehru SethuramanNot analyzed1 file
References
3Build Smart ERP Vendor Homepageproduct
https://ribccs.com/solutions/solution-buildsmart ExploitDB-50445exploit
https://www.exploit-db.com/exploits/50445