First published: Fri Jan 21 2022(Updated: )
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Budget And Expense Tracker System | =1.0 | |
Oretnom23 Budget And Expense Tracker System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40247 has been classified as a high severity SQL injection vulnerability.
To fix CVE-2021-40247, implement proper input validation and use prepared statements to mitigate SQL injection risks.
CVE-2021-40247 affects version 1.0 of the Budget and Expense Tracker System by Oretnom23.
CVE-2021-40247 enables attackers to execute arbitrary SQL commands through the vulnerable username field.
Currently, there is no official patch available for CVE-2021-40247, so users must apply manual remediation.