Record summary

CVE-2021-47777 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify database information.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List21.0817affected

Proofs of concept

1

Catalogued exploits

ExploitDBBuild Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)ExploitDB exploitby Nehru SethuramanNot analyzed1 file
ExploitDB

PoC details

References

3