Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.
References
Link | Resource |
---|---|
https://3xpl017.blogspot.com/2021/09/multiple-sql-injections-in.html | Third Party Advisory |
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-41492 | Exploit Third Party Advisory |
https://www.nu11secur1ty.com/2021/12/cve-2021-41492.html | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-11-03 20:15
Updated : 2024-02-28 18:48
NVD link : CVE-2021-41492
Mitre link : CVE-2021-41492
CVE.ORG link : CVE-2021-41492
JSON object : View
Products Affected
simple_cashiering_system_project
- simple_cashiering_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')