CVE-2021-47777
HIGHBuild Smart ERP 21.0817 - SQL Injection
Title source: llmDescription
Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify database information.
Exploits (1)
exploitdb
WORKING POC
by Nehru Sethuraman · textwebappsasp
https://www.exploit-db.com/exploits/50445
Scores
CVSS v3
8.2
EPSS
0.0005
EPSS Percentile
16.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-89
Status
published
Products (1)
Ribccs/Build Smart ERP
21.0817
Published
Jan 15, 2026
Tracked Since
Feb 18, 2026