CVE-2021-42670: SQL Injection
A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcementsstudent.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42670?
CVE-2021-42670 is a SQL injection vulnerability that exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page.
What is the severity of CVE-2021-42670?
The severity of CVE-2021-42670 is critical with a severity value of 9.8.
How does CVE-2021-42670 affect Engineers Online Portal?
CVE-2021-42670 allows a malicious user to extract sensitive data from the web server and potentially execute remote code.
How can I fix CVE-2021-42670?
To fix CVE-2021-42670, it is recommended to update the Sourcecodester Engineers Online Portal to a patched version that addresses the SQL injection vulnerability.
What are some references for CVE-2021-42670?
You can find more information about CVE-2021-42670 at the following references: [Link 1](https://github.com/TheHackingRabbi/CVE-2021-42670), [Link 2](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/janobe/CVE-nu11-101321), [Link 3](https://www.sourcecodester.com/php/13115/engineers-online-portal-php.html)