CVE-2021-29343

MEDIUM

Ovidentia < 6.7.7 - SQL Injection

Title source: rule

Description

Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code.

Exploits (1)

exploitdb WORKING POC
by Felipe Prates Donato · textwebappsphp
https://www.exploit-db.com/exploits/49707

Scores

CVSS v3 5.4
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-89
Status published
Products (1)
ovidentia/ovidentia 6.0.0 - 6.7.7
Published Mar 30, 2021
Tracked Since Feb 18, 2026