nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47766 CVE-2021-47766
HIGH
Kmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)
Record summary
CVE-2021-47766 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipulate database queries. Attackers can exploit this vulnerability using boolean-based, error-based, and time-based blind SQL injection techniques to potentially extract or manipulate database information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 1.1.0.205 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBKmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)ExploitDB exploitby Amel BOUZIANE-LEBLONDNot analyzed1 file
References
3Archived Kmaleon Software Product Pageproduct
https://web.archive.org/web/20210616143348/https://www.levelprograms.com/kmaleon-abogados ExploitDB-50499exploit
https://www.exploit-db.com/exploits/50499