Lucene search

K
cvelistMitreCVELIST:CVE-2021-41920
HistoryOct 08, 2021 - 3:37 p.m.

CVE-2021-41920

2021-10-0815:37:54
mitre
www.cve.org

0.003 Low

EPSS

Percentile

68.9%

webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.

0.003 Low

EPSS

Percentile

68.9%

Related for CVELIST:CVE-2021-41920