CVE-2021-45411
Summary
| CVE | CVE-2021-45411 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-12 17:15:00 UTC |
| Updated | 2022-01-20 15:24:00 UTC |
| Description | In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Printable Staff Id Card Creator System Project | Printable Staff Id Card Creator System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Printable Staff ID Card Creator System using PHP/MySQLi with Source Code | Free Source Code, Projects & Tutorials | MISC | www.sourcecodester.com | |
| Printable Staff ID Card Creator System 1.0 - SQLi & RCE via Arbitrary File Upload - PHP webapps Exploit | MISC | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.