ZeroHour

CVE-2021-44966

PoC
CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.

Vendors
phpgurukul
Products
employee record management system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.