CVE-2021-46200

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 21, 2022
Updated: Dec 27, 2024
CWE ID 89

Summary

CVE-2021-46200 is an SQL injection vulnerability discovered in the Sourcecodester Simple Music Cloud Community System 1.0. Attackers can exploit this weakness by manipulating the email parameter in the /music/ajax.php file, enabling them to inject malicious SQL queries. This could grant unauthorized access to sensitive data or even allow remote code execution, potentially leading to serious security breaches. System administrators are strongly advised to update to the latest version of the software or apply relevant patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share