Vulnerability Details CVE-2021-40908
SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.112
EPSS Ranking 93.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-40908
-
cpe:2.3:a:purchase_order_management_system_project:purchase_order_management_system:1.0