CVE-2021-33925 is a critical SQL Injection vulnerability affecting nitinparashar30's cms-corephp, specifically through commit bdabe52ef282846823bda102728a35506d0ec8f9. This flaw allows unauthenticated attackers to achieve escalated privileges by submitting a specially crafted login request. With a CVSS score of 9.8, the vulnerability presents a severe risk, as it can be exploited remotely with low complexity, leading to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, and public exploit code or significant community discussion is absent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021-05-19CPE matchmatch criteria | cpe:2.3:a:cms-corephp_project:cms-corephp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.