packetstormsecurity.com
http://packetstormsecurity.com/files/167026/WebTareas-2.4-SQL-Injection.html CVE-2021-43481
CRITICAL
WebTareas 2.4 - Blind SQLi (Authenticated)
Record summary
CVE-2021-43481 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWebTareas 2.4 - Blind SQLi (Authenticated)ExploitDB exploitby Behrad TaherNot analyzed1 file
References
4behradtaher.dev
https://behradtaher.dev/2021/11/05/Discovering-a-Blind-SQL-Injection-Whitebox-Approach nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-43481 sourceforge.net
https://sourceforge.net/projects/webtareas