CVE-2021-27581: SQL Injection
Published Mar 5, 2021
·Updated
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
Affected Software
1 affected component
Kentico Kentico CMS=5.5-r2
Event History
Mar 5, 2021
CVE Published
via MITRE·10:29 PM
Data Sourced
via MITRE·10:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-27581?
CVE-2021-27581 is rated as a high severity vulnerability due to its potential for SQL injection.
2
How does CVE-2021-27581 affect Kentico CMS?
CVE-2021-27581 allows attackers to exploit the Blog module in Kentico CMS 5.5 R2 build 5.5.3996 via the tagname parameter.
3
How do I fix CVE-2021-27581?
To fix CVE-2021-27581, upgrading to a patched version of Kentico CMS or applying any available security updates is recommended.
4
Can CVE-2021-27581 lead to data breaches?
Yes, successful exploitation of CVE-2021-27581 can lead to unauthorized access to the database, potentially resulting in data breaches.
5
Is CVE-2021-27581 specific to certain versions of Kentico CMS?
CVE-2021-27581 specifically affects Kentico CMS version 5.5 R2 build 5.5.3996.