CVE-2021-36621

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
30/07/2021
Last modified:
18/10/2021

Description

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:online_covid_vaccination_scheduler_system_project:online_covid_vaccination_scheduler_system:1.0:*:*:*:*:*:*:*