Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-102010
HistoryOct 31, 2021 - 12:00 a.m.

News Portal Project SQL Injection Vulnerability (CNVD-2021-102010)

2021-10-3100:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
sql injection
news portal project
version 3.1
validation
external input
category
subcategory
sucatdescription
username parameters
illegal commands
sensitive data
vulnerability.

EPSS

0.01

Percentile

83.6%

News Portal Project is an open source news portal project. news Portal Project has a SQL injection vulnerability in version 3.1, which stems from the lack of validation of external input for the category, subcategory, sucatdescription, username parameters of the application. SQL statement validation. An attacker could use the vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.01

Percentile

83.6%

Related for CNVD-2021-102010