Record summary

CVE-2021-37589 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Virtua Cobranca before 12R allows SQL Injection on the login page.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBVirtua Software Cobranca 12S - SQLiExploitDB exploitby Luca RegneNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHVirtua Software Cobranca <12R - Blind SQL InjectionCVSS 7.5

Virtua Cobranca before 12R allows blind SQL injection on the login page.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the underlying system.

Remediation

Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in Virtua Software Cobranca <12R.

WeaknessesCWE-89
Authorsprincechaddha
Template tagscvecve2021virtuasqlivirtuasoftwarevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:virtuasoftware:cobranca:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:876876147
FOFA: icon_hash=876876147

Source: ProjectDiscovery

References

4