CVE-2021-42169

The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:simple_payroll_system_with_dynamic_tax_bracket_project:simple_payroll_system_with_dynamic_tax_bracket:-:*:*:*:*:*:*:*

Information

Published : 2021-10-22 07:15

Updated : 2021-12-03 12:58


NVD link : CVE-2021-42169

Mitre link : CVE-2021-42169


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

simple_payroll_system_with_dynamic_tax_bracket_project

  • simple_payroll_system_with_dynamic_tax_bracket