Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47777. PoCs published by Nehru Sethuraman.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated SQL injection vulnerability in Build Smart ERP 21.0817 via the 'eidValue' parameter. The payload uses a time-based delay to confirm the vulnerability, indicating a stacked query SQL injection.
Description
Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify database information.
Exploits (1)
This exploit demonstrates an unauthenticated SQL injection vulnerability in Build Smart ERP 21.0817 via the 'eidValue' parameter. The payload uses a time-based delay to confirm the vulnerability, indicating a stacked query SQL injection.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N