First published: Fri Nov 05 2021(Updated: )
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a remote code execution on the remote web server.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Engineers Online Portal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42668 is a SQL Injection vulnerability that exists in Sourcecodester Engineers Online Portal in PHP.
CVE-2021-42668 can be exploited by an attacker by injecting malicious SQL statements through the 'id' parameter in the my_classmates.php web page.
CVE-2021-42668 has a severity level of critical, with a CVSS score of 9.8.
An attacker can exploit CVE-2021-42668 to extract sensitive data from the web server and in some cases achieve remote code execution.
Yes, you can find more information about CVE-2021-42668 on the following links: [link1], [link2], [link3]