10
CVSSv2

CVE-2021-42077

Published: 08/11/2021 Updated: 09/11/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP Event Calendar prior to 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kaysongroup php event calendar

Exploits

PHP Event Calendar Lite Edition suffers from a remote SQL injection vulnerability that allows for authentication bypass ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [SYSS-2021-048] PHP Event Calendar - SQL Injection (CVE-2021-42077) <!--X-Subject-Header-End--> <!--X-Head-of-Message- ...