CVE-2021-29343

MEDIUM

Ovidentia CMS 6.0.0-6.7.7 - SQL Injection via Index.php ID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-29343. PoCs published by Felipe Prates Donato.

AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in Ovidentia 6, leveraging a UNION-based attack to extract table and column names from the 'mysql' database schema. The payload is injected via the 'id' parameter in the delegat module.

Description

Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code.

Exploits (1)

exploitdb WORKING POC
by Felipe Prates Donato · textwebappsphp
https://www.exploit-db.com/exploits/49707

This exploit demonstrates an authenticated SQL injection vulnerability in Ovidentia 6, leveraging a UNION-based attack to extract table and column names from the 'mysql' database schema. The payload is injected via the 'id' parameter in the delegat module.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Ovidentia 6
Auth required
Prerequisites: Authenticated access to the Ovidentia application · Target must be running Ovidentia version 6
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
http://ovidentia.org
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49707

Scores

CVSS v3 5.4
EPSS 0.0075
EPSS Percentile 50.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-89
Status published
Products (1)
ovidentia/ovidentia 6.0.0 - 6.7.7
Published Mar 30, 2021
Tracked Since Feb 18, 2026