CVE-2021-40578
Summary
| CVE | CVE-2021-40578 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-07 22:15:00 UTC |
| Updated | 2023-11-07 03:38:00 UTC |
| Description | Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Online Enrollment Management System Project | Online Enrollment Management System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021–40578.. Authenticated Blind & Error based SQL… | by Tushar Jadhav | Nov, 2021 | Medium | MISC | medium.com | |
| CVE-nu11secur1ty/vendors/janobe/Online-Enrollment-Management-System at main · nu11secur1ty/CVE-nu11secur1ty · GitHub | MISC | github.com | |
| Online-Enrollment-Management-System-SQL-Injection | MISC | www.nu11secur1ty.com | |
| CVE-2021–40578.. Authenticated Blind & Error based SQL… | by Tushar Jadhav | Nov, 2021 | Medium | medium.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.