CVE-2021-26837: SQL Injection
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26837?
CVE-2021-26837 is a SQL Injection vulnerability in the SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18.
How severe is CVE-2021-26837?
CVE-2021-26837 has a severity of 9.8 (critical).
What can an attacker do with CVE-2021-26837?
With CVE-2021-26837, attackers can execute arbitrary code, escalate privileges, and gain sensitive information.
How can I fix the CVE-2021-26837 vulnerability?
To fix the CVE-2021-26837 vulnerability, update to Fortra DeliverNow version 1.2.18 or later.
Where can I find more information about CVE-2021-26837?
More information about CVE-2021-26837 can be found at the following links: [link1](https://community.helpsystems.com/knowledge-base/rjs/delivernow/overview/), [link2](https://susos.co/blog/f/cve-disclosure-sedric-louissaints-discovery-of-sql-injection-in)