Fiche vulnérabilité
CVE-2021-44966 : faille critique phpgurukul employee record management… (CVSS 9.8)
Description
SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 13 déc. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- phpgurukul employee record management system