Record summary

CVE-2021-43481 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWebTareas 2.4 - Blind SQLi (Authenticated)ExploitDB exploitby Behrad TaherNot analyzed1 file
ExploitDB

PoC details

References

4