CVE-2021-42666: SQL Injection
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to quizquestion.php, which could let a malicious user extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42666?
CVE-2021-42666 is a SQL Injection vulnerability in the Sourcecodester Engineers Online Portal in PHP.
How does CVE-2021-42666 work?
CVE-2021-42666 allows a malicious user to extract sensitive data from the web server and potentially achieve remote code execution.
What is the severity rating of CVE-2021-42666?
CVE-2021-42666 has a severity rating of 8.8, which is considered high.
What software is affected by CVE-2021-42666?
The Engineers Online Portal version 1.0 is affected by CVE-2021-42666.
How can I fix CVE-2021-42666?
To fix CVE-2021-42666, it is recommended to update the Sourcecodester Engineers Online Portal to a patched version.