Record summary

CVE-2021-47846 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police, incharge, user, and HQ login endpoints.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBDigital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass)ExploitDB exploitby GaluhIDNot analyzed1 file
ExploitDB

PoC details

References

5