PoC Index

CVE-2021-44966

HIGH 10.0EPSS 2.1%

SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
2.08% chance of exploitation in the next 30 days, 80th percentile
Published
2021-12-13
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related