8.1
CVSSv3

CVE-2021-36621

Published: 30/07/2021 Updated: 18/10/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

online covid vaccination scheduler system project online covid vaccination scheduler system 1.0

Exploits

Covid Vaccination Scheduler System version 10 suffers from cross site scripting and remote SQL injection vulnerabilities Original discovery of SQL injection in this version is attributed to faisalfs10x in July of 2021 ...