In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-01-12T16:34:41

Updated: 2022-01-12T16:34:41

Reserved: 2021-12-20T00:00:00


Link: CVE-2021-45411

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-12T17:15:08.320

Modified: 2022-01-20T15:24:02.163


Link: CVE-2021-45411

JSON object: View

cve-icon Redhat Information

No data.

CWE