CVE-2021-42077

CVE-2021-42077

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

Source: CVE-2021-42077

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다