{"api_version":"1","generated_at":"2026-07-24T20:09:49+00:00","cve":"CVE-2021-45411","urls":{"html":"https://cve.report/CVE-2021-45411","api":"https://cve.report/api/cve/CVE-2021-45411.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-45411","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-45411"},"summary":{"title":"CVE-2021-45411","description":"In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-01-12 17:15:00","updated_at":"2022-01-20 15:24:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://www.sourcecodester.com/php/12802/php-staff-id-card-creation-and-printing-system.html","name":"https://www.sourcecodester.com/php/12802/php-staff-id-card-creation-and-printing-system.html","refsource":"MISC","tags":[],"title":"Printable Staff ID Card Creator System using PHP/MySQLi with Source Code  | Free Source Code, Projects & Tutorials","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/49877","name":"https://www.exploit-db.com/exploits/49877","refsource":"MISC","tags":[],"title":"Printable Staff ID Card Creator System 1.0 - SQLi & RCE via Arbitrary File Upload - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-45411","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-45411","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"45411","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"printable_staff_id_card_creator_system_project","cpe5":"printable_staff_id_card_creator_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-45411","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.sourcecodester.com/php/12802/php-staff-id-card-creation-and-printing-system.html","refsource":"MISC","name":"https://www.sourcecodester.com/php/12802/php-staff-id-card-creation-and-printing-system.html"},{"url":"https://www.exploit-db.com/exploits/49877","refsource":"MISC","name":"https://www.exploit-db.com/exploits/49877"}]}},"nvd":{"publishedDate":"2022-01-12 17:15:00","lastModifiedDate":"2022-01-20 15:24:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:printable_staff_id_card_creator_system_project:printable_staff_id_card_creator_system:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"45411","Ordinal":"223535","Title":"CVE-2021-45411","CVE":"CVE-2021-45411","Year":"2021"},"notes":[]}}}