First published: Fri Nov 05 2021(Updated: )
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quiz_question.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Engineers Online Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42666 is a SQL Injection vulnerability in the Sourcecodester Engineers Online Portal in PHP.
CVE-2021-42666 allows a malicious user to extract sensitive data from the web server and potentially achieve remote code execution.
CVE-2021-42666 has a severity rating of 8.8, which is considered high.
The Engineers Online Portal version 1.0 is affected by CVE-2021-42666.
To fix CVE-2021-42666, it is recommended to update the Sourcecodester Engineers Online Portal to a patched version.