
CVE-2021-42665 - SQL Injection authentication bypass vulnerability in the Engineers online portal system.
CVE-2021-42665 - SQL Injection authentication bypass vulnerability in the Engineers online portal system.
An SQL Injection vulnerability exists in the Engineers Online Portal login form which can allow an attacker to bypass authentication.
Affected components -
Vulnerable page - login.php
Vulnerable parameter - "username", "password"
The following payload will allow you to bypass the authentication mechanism of the Engineers Online Portal login form -
sqli' OR '1'='1';-- -

https://www.exploit-db.com/exploits/50452
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42665
https://nvd.nist.gov/vuln/detail/CVE-2021-42665
Alon Leviev(0xDeku), 22 October, 2021.