← All CVEs

CVE-2021-42671

high · 7.5

An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.

7.5
CVSS
19.7%
EPSS (exploit prob.)
97th
EPSS percentile
2021-11-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-425

Affected products

VendorProductAffected versions
engineers_online_portal_projectengineers_online_portalall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-42671