CVE-2021-46200
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2021-46200 is an SQL injection vulnerability discovered in the Sourcecodester Simple Music Cloud Community System 1.0. Attackers can exploit this weakness by manipulating the email parameter in the /music/ajax.php file, enabling them to inject malicious SQL queries. This could grant unauthorized access to sensitive data or even allow remote code execution, potentially leading to serious security breaches. System administrators are strongly advised to update to the latest version of the software or apply relevant patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.