Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-42077
HistoryNov 08, 2021 - 4:15 a.m.

Sql injection

2021-11-0804:15:00
PRIOn knowledge base
www.prio-n.com
3

9.7 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.9%

PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the login form.

CPENameOperatorVersion
php_event_calendareq< 202193

9.7 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.9%