CVE-2021-37497: SQL Injection
Published Feb 3, 2023
·Updated
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
Affected Software
1 affected component
Pbootcms Pbootcms=3.0.5
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-37497?
The severity of CVE-2021-37497 is critical (9.8).
2
How does CVE-2021-37497 affect PbootCMS 3.0.5?
CVE-2021-37497 allows remote attackers to run arbitrary SQL commands via crafted GET request in PbootCMS 3.0.5.
3
How can I fix CVE-2021-37497 in PbootCMS 3.0.5?
To fix CVE-2021-37497 in PbootCMS 3.0.5, it is recommended to apply the latest patch or upgrade to a patched version provided by the vendor.
4
What is CWE-89?
CWE-89 is a vulnerability type called 'Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')'.
5
Where can I find more information about CVE-2021-37497?
More information about CVE-2021-37497 can be found at the following references: [GitHub Issue](https://github.com/penson233/Vuln/issues/3), [Vendor Website](https://www.pbootcms.com/).