CVE-2021-29343
MEDIUMOvidentia CMS 6.0.0-6.7.7 - SQL Injection via Index.php ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-29343. PoCs published by Felipe Prates Donato.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in Ovidentia 6, leveraging a UNION-based attack to extract table and column names from the 'mysql' database schema. The payload is injected via the 'id' parameter in the delegat module.
Description
Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code.
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in Ovidentia 6, leveraging a UNION-based attack to extract table and column names from the 'mysql' database schema. The payload is injected via the 'id' parameter in the delegat module.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N