CVE-2021-44098
Published
CVSS v3
9.8
CRITICAL
CVSS v2
7.5
HIGH
Affected
1
PROJECT
Description
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.
This simple Expense Management System allows you to keep a detailed record of all your expenses. To make a record of a new expense just enter: description, amount and date. All fields are validated using JavaScript. Once you have made your registration you will be able to visualize it in the table which allows you to organize the columns and search for expenses.