CVE-2021-29343
MEDIUMOvidentia < 6.7.7 - SQL Injection
Title source: ruleDescription
Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code.
Exploits (1)
exploitdb
WORKING POC
by Felipe Prates Donato · textwebappsphp
https://www.exploit-db.com/exploits/49707
Scores
CVSS v3
5.4
EPSS
0.0019
EPSS Percentile
40.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-89
Status
published
Products (1)
ovidentia/ovidentia
6.0.0 - 6.7.7
Published
Mar 30, 2021
Tracked Since
Feb 18, 2026