Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-85278
HistoryOct 11, 2021 - 12:00 a.m.

webTareas SQL Injection Vulnerability

2021-10-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
4

0.003 Low

EPSS

Percentile

68.9%

webTareas is a Web-based open source collaboration tool. The product supports project management, bug tracking, content management and meeting management. webTareas 2.4 and earlier versions have security vulnerabilities that allow unauthenticated users to execute time- and boolean-based SQL injections on the endpoint "/includes/library.php" via HTTP POST parameters such as "sor_cible", "sor_champs" and "sor_ordre". /library.php" on the endpoint to perform time- and Boolean-based SQL injection. An attacker can exploit the vulnerability to access all data in the database and gain access to the webTareas application.

CPENameOperatorVersion
webtareas webtareasle2.4

0.003 Low

EPSS

Percentile

68.9%

Related for CNVD-2021-85278