CVE-2021-40596: SQL Injection
Published Jan 24, 2022
·Updated
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the facultyid parameter.
Affected Software
2 affected components
oretnom23 Online Learning System=2.0
Online Learning System Project Online Learning System=2.0
Event History
Jan 24, 2022
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-40596?
CVE-2021-40596 has a medium severity level due to its potential for SQL injection attacks.
2
How do I fix CVE-2021-40596?
To fix CVE-2021-40596, validate and sanitize user inputs, especially the faculty_id parameter.
3
What are the potential impacts of CVE-2021-40596?
CVE-2021-40596 can allow attackers to execute arbitrary SQL commands, potentially leading to data breaches.
4
Is CVE-2021-40596 present in all versions of the Online Learning System?
CVE-2021-40596 specifically affects Online Learning System v2.0.
5
Who is responsible for CVE-2021-40596?
CVE-2021-40596 was identified in software developed by oretnom23.