Vulnerability Description
An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Covid 19 Testing Management System Project | Covid 19 Testing Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/unyasoft/CTMSExploitThird Party Advisory
- https://www.nu11secur1ty.com/2021/11/ctms.htmlExploitThird Party Advisory
- https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/unyasoft/CTMSExploitThird Party Advisory
- https://www.nu11secur1ty.com/2021/11/ctms.htmlExploitThird Party Advisory
FAQ
What is CVE-2021-44245?
CVE-2021-44245 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.
How severe is CVE-2021-44245?
CVE-2021-44245 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-44245?
Check the references section above for vendor advisories and patch information. Affected products include: Covid 19 Testing Management System Project Covid 19 Testing Management System.