.. / CVE-2021-43510

Exploit for Sourcecodester Simple Client Management System 1.0 - SQL Injection (CVE-2021-43510)

Description:

Sourcecodester Simple Client Management System 1.0 contains a SQL injection vulnerability via the username field in login.php. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Nuclei Template

View the template here CVE-2021-43510.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-43510.yaml
Copy

References:

https://github.com/r4hn1/Simple-Client-Management-System-Exploit
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2021-43510
https://www.sourcecodester.com/php/15027/simple-client-management-system-php-source-code.html
https://github.com/r4hn1/Simple-Client-Management-System-Exploit/blob/main/CVE-2021-43510