Description
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
Related CPE's
References
https://github.com/Ni7inSharma/CVE-2021-41511
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-41511
https://www.exploit-db.com/exploits/50372
https://www.nu11secur1ty.com/2021/10/cve-2021-41511.html
https://github.com/Ni7inSharma/CVE-2021-41511
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-41511
https://www.exploit-db.com/exploits/50372
https://www.nu11secur1ty.com/2021/10/cve-2021-41511.html
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-04T11:15:08.010Z
4 years agoLast modified
2024-11-21T05:26:20.697Z
1 year ago