Aller au contenu

Fiche vulnérabilité

CVE-2021-44599 : faille élevée online enrollment management system… (CVSS 7.5)

Description

The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. A crafted payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve sensitive information for all users of this system.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
23 déc. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • online enrollment management system project online enrollment management system

Références

Rechercher une autre vulnérabilité dans la base CVE