CVE-2021-3021: SQL Injection
ISPConfig before 3.2.2 allows SQL injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ISPConfigto a version that resolves this vulnerability.Fixed in 3.2.2
Event History
Frequently Asked Questions
What is CVE-2021-3021?
CVE-2021-3021 is a vulnerability that allows SQL injection in ISPConfig before version 3.2.2.
What is the severity of CVE-2021-3021?
The severity of CVE-2021-3021 is critical with a CVSS score of 9.8.
How does CVE-2021-3021 affect ISPConfig?
CVE-2021-3021 affects ISPConfig versions before 3.2.2, allowing SQL injection.
How can I fix CVE-2021-3021?
To fix CVE-2021-3021, update ISPConfig to version 3.2.2 or above.
Are there any references related to CVE-2021-3021?
Yes, you can find more information about CVE-2021-3021 in the following references: [https://twitter.com/ispconfig/status/1346142615511724032](https://twitter.com/ispconfig/status/1346142615511724032) and [https://www.ispconfig.org/blog/ispconfig-3-2-2-released-important-security-update/](https://www.ispconfig.org/blog/ispconfig-3-2-2-released-important-security-update/).