CVE-2021-41511
9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to bypass authentication.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.34% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-10-04 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| lodging reservation management system project | lodging reservation management system |
References
- http://packetstormsecurity.com/files/164366/Lodging-Reservation-Management-System-1.0-SQL-Injection.html
- https://github.com/Ni7inSharma/CVE-2021-41511
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-41511
- https://streamable.com/9fq8uw
- https://www.exploit-db.com/exploits/50372
- https://www.nu11secur1ty.com/2021/10/cve-2021-41511.html
- https://www.sourcecodester.com/php/14883/lodging-reservation-management-system-php-free-source-code.html
- http://packetstormsecurity.com/files/164366/Lodging-Reservation-Management-System-1.0-SQL-Injection.html
- https://github.com/Ni7inSharma/CVE-2021-41511
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-41511
- https://streamable.com/9fq8uw
- https://www.exploit-db.com/exploits/50372
- https://www.nu11secur1ty.com/2021/10/cve-2021-41511.html
- https://www.sourcecodester.com/php/14883/lodging-reservation-management-system-php-free-source-code.html
→ the Explorer · watch your stack · NVD