CVE-2021-42580: SQL Injection
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42580?
CVE-2021-42580 has a high severity rating due to its potential for unauthenticated remote code execution.
How do I fix CVE-2021-42580?
To fix CVE-2021-42580, ensure that you apply patches provided by the software vendor, implement input validation in authentication mechanisms, and restrict file upload capabilities.
What are the main vulnerabilities in CVE-2021-42580?
CVE-2021-42580 contains SQL injection vulnerabilities allowing authentication bypass and unauthenticated file uploads.
Which systems are affected by CVE-2021-42580?
CVE-2021-42580 affects version 2.0 of the Online Learning System by both Online Learning System Project and Oretnom23.
Can CVE-2021-42580 be exploited remotely?
Yes, CVE-2021-42580 can be exploited remotely due to the nature of the vulnerabilities allowing unauthenticated access.