CVE-2021-31586: SQL Injection
Published Jun 23, 2021
·Updated
Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
Affected Software
1 affected component
Accellion kiteworks<7.4.0
Event History
Jun 23, 2021
CVE Published
via MITRE·11:20 AM
Data Sourced
via MITRE·11:20 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-31586.
2
What is the severity of CVE-2021-31586?
The severity of CVE-2021-31586 is high with a CVSS score of 8.8.
3
How does CVE-2021-31586 impact Accellion Kiteworks?
CVE-2021-31586 allows an authenticated user to perform SQL Injection via LDAPGroup Search in Accellion Kiteworks before version 7.4.0.
4
How can an authenticated user exploit CVE-2021-31586?
An authenticated user can exploit CVE-2021-31586 by performing SQL Injection via LDAPGroup Search.
5
How can I fix CVE-2021-31586?
To fix CVE-2021-31586, update Accellion Kiteworks to version 7.4.0 or later.