Lucene search

K
cvelistMitreCVELIST:CVE-2021-37475
HistoryJul 26, 2021 - 5:15 p.m.

CVE-2021-37475

2021-07-2617:15:06
mitre
www.cve.org
2
navigatecms
sql injection
templates.php
parameter vulnerability
arbitrary query execution
backend database

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

69.0%

In NavigateCMS version 2.9.4 and below, function in templates.php is vulnerable to sql injection on parameter template-properties-order, which results in arbitrary sql query execution in the backend database.

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

69.0%

Related for CVELIST:CVE-2021-37475