CVE-2021-42671
Last modified
CVE-2021-42671 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.. EPSS estimates a 19.68% chance of exploitation in the next 30 days.
Description
An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Engineers Online Portal Project | Engineers Online Portal | All versions |
References
- https://github.com/TheHackingRabbi/CVE-2021-42671Exploit, Third Party Advisory
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-42671Exploit, Third Party Advisory
- https://www.sourcecodester.com/php/13115/engineers-online-portal-php.htmlProduct, Third Party Advisory
- https://github.com/TheHackingRabbi/CVE-2021-42671Exploit, Third Party Advisory
- https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-42671Exploit, Third Party Advisory
- https://www.sourcecodester.com/php/13115/engineers-online-portal-php.htmlProduct, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-42671?
How severe is CVE-2021-42671?
How do I fix CVE-2021-42671?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-42666A SQL Injection vulnerability exists in Sourcecodester Engin…8.8
- CVE-2021-42667A SQL Injection vulnerability exists in Sourcecodester Onlin…9.8
- CVE-2021-42668A SQL Injection vulnerability exists in Sourcecodester Engin…9.8
- CVE-2021-42669A file upload vulnerability exists in Sourcecodester Enginee…9.8
- CVE-2021-4267A vulnerability classified as problematic was found in tad_d…6.1
- CVE-2021-42670A SQL injection vulnerability exists in Sourcecodester Engin…9.8
- CVE-2021-42675Kreado Kreasfero 1.5 does not properly sanitize uploaded fil…9.8
- CVE-2021-4268A vulnerability, which was classified as problematic, was fo…8.8
- CVE-2021-42681A Buffer Overflow vulnerability exists in Accops HyWorks DVM…8.8
- CVE-2021-42682An Integer Overflow vulnerability exists in Accops HyWorks D…8.8
- CVE-2021-42683A Buffer Overflow vulnerability exists in Accops HyWorks Win…8.8
- CVE-2021-42685An Integer Overflow vulnerability exists in Accops HyWorks D…8.8
Are you affected by CVE-2021-42671?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
