Aller au contenu

Fiche vulnérabilité

CVE-2021-41920 : faille élevée webtareas project webtareas (CVSS 7.5)

Description

webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
8 oct. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • webtareas project webtareas

Références

Rechercher une autre vulnérabilité dans la base CVE