CVE-2021-42580
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 15, 2021
Updated: Dec 18, 2024
CWE ID 89
Summary
CVE-2021-42580 is a vulnerability affecting the Sourcecodester Online Learning System 2.0. Hackers can exploit this issue through sql injection in the admin login file (/admin/login.php) to bypass authentication. Additionally, there's an authenticated file upload vulnerability in the Master.php file. By combining these two weaknesses, an attacker can achieve unauthenticated remote command execution on the system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.