CVE-2021-31632: SQL Injection
Published Dec 6, 2021
·Updated
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
Affected Software
1 affected component
b2evolution b2evolution cms=7.2.3
Event History
Dec 6, 2021
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this b2evolution CMS vulnerability?
The vulnerability ID for this b2evolution CMS vulnerability is CVE-2021-31632.
2
What is the severity of CVE-2021-31632?
The severity of CVE-2021-31632 is critical with a severity value of 9.8.
3
How does CVE-2021-31632 affect b2evolution CMS?
CVE-2021-31632 affects b2evolution CMS version 7.2.3.
4
What is the impact of CVE-2021-31632?
The impact of CVE-2021-31632 is the ability for attackers to execute arbitrary code via a crafted input.
5
Is there a fix available for CVE-2021-31632?
At the time of writing, there is no known fix available for CVE-2021-31632. It is recommended to follow the mitigation steps provided by the vendor.