SQL Injection Vulnerability in EGavilan Media Expense-Management-System
CVE-2021-44098
9.8CRITICAL
What is CVE-2021-44098?
The EGavilan Media Expense-Management-System version 1.0 is susceptible to SQL Injection vulnerability through an accessible endpoint at /expense_action.php. This security flaw allows remote attackers to execute arbitrary SQL commands, potentially compromising the application’s SQL database and exposing sensitive data.
