Record summary

CVE-2021-45793 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHSlims9 Bulian 9.4.2 - SQL InjectionCVSS 7.5

Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.

Impact

Authenticated attackers can exploit SQL injection in the comment field to extract database contents including user credentials and sensitive library data.

Remediation

Upgrade to Slims9 Bulian version 9.4.3 or later.

WeaknessesCWE-89
Authorsnblirwn
Template tagscve2021cveslimssqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:slims:senayan_library_management_system:9.4.2:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2