9.8
CVSSv3

CVE-2021-38833

Published: 13/09/2021 Updated: 05/11/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows malicious users to execute arbitrary SQL statements and to gain RCE.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apartment visitors management system project apartment visitors management system 1.0

Github Repositories

AVMS-exploit

CVE-2021-38833 - SQL injection to RCE exploit in Apartment Visitors Management System (AVMS) v10 phpgurukulcom/apartment-visitors-management-system-using-php-and-mysql/ How it works The exploit uses an union-based SQL injection and into_outfile functionality to first upload PHP webshell on the server and then execute reverse shell payload (base64-encoded) on the targ