CVE-2021-44653 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 6% (pctl 93)
Patch early
A public exploit exists.
Description
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.97% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-12-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| oretnom23 | online magazine management system |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Online Magazine Management System 1.0 - SQLi Authentication Bypass | 2021-12-03 |
References
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44653
- https://www.exploit-db.com/exploits/50561
- https://www.nu11secur1ty.com/2021/12/cve-2021-44653.html
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44653
- https://www.exploit-db.com/exploits/50561
- https://www.nu11secur1ty.com/2021/12/cve-2021-44653.html
→ the Explorer · watch your stack · NVD