CVE-2021-44098: SQL Injection
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expenseaction.php. This allows a remote attacker to compromise Application SQL database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44098?
CVE-2021-44098 is a vulnerability in EGavilan Media Expense-Management-System 1.0 that allows remote attackers to perform SQL Injection and compromise the application's SQL database.
How severe is CVE-2021-44098?
CVE-2021-44098 has a severity rating of critical with a CVSS score of 9.8.
How does CVE-2021-44098 affect EGavilan Media Expense-Management-System?
CVE-2021-44098 affects EGavilan Media Expense-Management-System 1.0, allowing remote attackers to exploit a SQL Injection vulnerability in /expense_action.php.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-44098?
CVE-2021-44098 is classified under CWE-89, which refers to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').
How can I mitigate the vulnerability described in CVE-2021-44098?
To mitigate CVE-2021-44098, it is recommended to ensure proper input validation and sanitization to prevent SQL Injection attacks in EGavilan Media Expense-Management-System 1.0.