Lucene search

K
cvelistMitreCVELIST:CVE-2021-45406
HistoryJan 14, 2022 - 7:25 p.m.

CVE-2021-45406

2022-01-1419:25:16
mitre
www.cve.org
1
salonerp
sql injection
vulnerability
report generation
admin password hash
decryption

AI Score

9.1

Confidence

High

EPSS

0.005

Percentile

76.9%

In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using ‘sql’ parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.

AI Score

9.1

Confidence

High

EPSS

0.005

Percentile

76.9%

Related for CVELIST:CVE-2021-45406