CVE-2021-44653 describes a critical SQL injection authentication bypass vulnerability in Online Magazine Management System 1.0, specifically affecting the oretnom23 online_magazine_management_system. This flaw allows an unauthenticated attacker to gain administrative access to the application's Admin panel by exploiting a SQL injection vulnerability within the login form. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a low attack complexity and no user interaction required, enabling full compromise of confidentiality, integrity, and availability. While not observed in active exploitation and not on the CISA KEV catalog, public exploit code exists on ExploitDB (EDB-50561), though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:oretnom23:online_magazine_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.