113 lines
3.3 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2021-45411",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-01-12T17:15:08.320",
"lastModified": "2022-01-20T15:24:02.163",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution."
},
{
"lang": "es",
"value": "En Sourcecodetester Printable Staff ID Card Creator System versi\u00f3n 1.0, despu\u00e9s de comprometer la base de datos por medio de SQLi, un atacante puede iniciar sesi\u00f3n y aprovechar una vulnerabilidad de carga de archivos arbitraria para obtener una ejecuci\u00f3n de c\u00f3digo remota"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-434"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:printable_staff_id_card_creator_system_project:printable_staff_id_card_creator_system:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "66FE6CF1-5371-47E0-8FFA-1DAA8D25DA9D"
}
]
}
]
}
],
"references": [
{
"url": "https://www.exploit-db.com/exploits/49877",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://www.sourcecodester.com/php/12802/php-staff-id-card-creation-and-printing-system.html",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}