CVE-2021-36520: SQL Injection
Published Apr 16, 2023
·Updated
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
Affected Software
1 affected component
Washington I-tech Trainsmart=r1044
Event History
Apr 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-36520?
CVE-2021-36520 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2021-36520?
To fix CVE-2021-36520, you should validate and sanitize user inputs in the affected evaluation/assign-evaluation?id= URI.
3
What systems are affected by CVE-2021-36520?
CVE-2021-36520 affects the I-Tech Trainsmart version r1044.
4
What type of vulnerability is CVE-2021-36520?
CVE-2021-36520 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
Can CVE-2021-36520 lead to data breaches?
Yes, exploiting CVE-2021-36520 can potentially lead to unauthorized access and data breaches.