CVE-2021-42671
high · 7.5An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.
7.5
CVSS
19.7%
EPSS (exploit prob.)
97th
EPSS percentile
2021-11-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-425
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| engineers_online_portal_project | engineers_online_portal | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/TheHackingRabbi/CVE-2021-42671
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-42671
- https://www.sourcecodester.com/php/13115/engineers-online-portal-php.html
- https://github.com/TheHackingRabbi/CVE-2021-42671
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-42671
- https://www.sourcecodester.com/php/13115/engineers-online-portal-php.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-42671