CVE-2021-26200: SQL Injection
Published Feb 15, 2021
·Updated
The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user.
Affected Software
1 affected component
Library System Project Library System=1.0
Event History
Feb 15, 2021
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
Description
Frequently Asked Questions
1
What is CVE-2021-26200?
CVE-2021-26200 is a vulnerability in the user area for Library System 1.0 that allows SQL injection and enables a user to bypass authentication and login as the admin user.
2
How severe is CVE-2021-26200?
CVE-2021-26200 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2021-26200 affect Library System 1.0?
CVE-2021-26200 affects Library System 1.0 in the user area, allowing for SQL injection and bypassing of authentication to login as the admin user.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-26200?
The Common Weakness Enumeration (CWE) ID for CVE-2021-26200 is CWE-89.
5
How can I fix CVE-2021-26200?
To fix CVE-2021-26200, it is recommended to apply the latest patch or update provided by Library System Project for Library System 1.0.