CVE-2021-41661: SQL Injection
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41661?
CVE-2021-41661 is a SQL injection vulnerability in Church Management System version 1.0.
How does CVE-2021-41661 work?
CVE-2021-41661 is exploited by creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory, leading to remote code execution on the web server by uploading a PHP webshell.
What is the severity of CVE-2021-41661?
CVE-2021-41661 has a severity rating of 9.8 (Critical).
How can I fix CVE-2021-41661?
To fix CVE-2021-41661, it is recommended to update Church Management System to a version that addresses the SQL injection vulnerability.
Where can I find more information about CVE-2021-41661?
You can find more information about CVE-2021-41661 at the following link: [https://github.com/janikwehrli1/0dayHunt/blob/main/Church_Managementv1.0_RCE.py]