CVE-2021-42580

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 15, 2021
Updated: Dec 18, 2024
CWE ID 89

Summary

CVE-2021-42580 is a vulnerability affecting the Sourcecodester Online Learning System 2.0. Hackers can exploit this issue through sql injection in the admin login file (/admin/login.php) to bypass authentication. Additionally, there's an authenticated file upload vulnerability in the Master.php file. By combining these two weaknesses, an attacker can achieve unauthenticated remote command execution on the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share