CVE-2021-44655

Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application.
References
Link Resource
https://www.exploit-db.com/exploits/50560 Exploit Third Party Advisory VDB Entry
https://www.nu11secur1ty.com/2021/12/cve-2021-44655.html Exploit Third Party Advisory
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44655 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:online_pre-owned\/used_car_showroom_management_system_project:online_pre-owned\/used_car_showroom_management_system:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-12-15 16:15

Updated : 2022-03-29 16:28


NVD link : CVE-2021-44655

Mitre link : CVE-2021-44655


JSON object : View

Products Affected

online_pre-owned\/used_car_showroom_management_system_project

  • online_pre-owned\/used_car_showroom_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')