Fiche vulnérabilité
CVE-2021-43420 : faille critique online payment hub project online… (CVSS 9.8)
Description
SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 24 janv. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- online payment hub project online payment hub