CVE-2021-37782: SQL Injection
Published Oct 28, 2022
·Updated
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
Affected Software
1 affected component
Phpgurukul Employee Record Management System=1.2
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-37782?
The severity of CVE-2021-37782 is critical.
2
How does the CVE-2021-37782 vulnerability occur?
CVE-2021-37782 vulnerability occurs in the Employee Record Management System v1.2 due to an SQL Injection vulnerability in the editempprofile.php file.
3
How can I check if I am affected by CVE-2021-37782?
If you are using Employee Record Management System v1.2, you may be affected by CVE-2021-37782.
4
What is the CWE ID for CVE-2021-37782?
The CWE ID for CVE-2021-37782 is CWE-89.
5
How can I mitigate the vulnerability in CVE-2021-37782?
To mitigate the vulnerability in CVE-2021-37782, you should apply the latest security patch provided by the developer of the Employee Record Management System or upgrade to a newer version.