CVE-2021-38732: SQL Injection
Published Oct 28, 2022
·Updated
SEMCMS SHOP v 1.1 is vulnerable to SQL via AntMessage.php.
Affected Software
1 affected component
Sem-cms Semcms=1.1
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38732?
CVE-2021-38732 is a vulnerability in SEMCMS SHOP v 1.1 that allows SQL injection via Ant_Message.php.
2
How severe is CVE-2021-38732?
CVE-2021-38732 has a severity rating of critical, with a CVSS score of 9.8.
3
How does CVE-2021-38732 affect SEMCMS SHOP v 1.1?
CVE-2021-38732 affects SEMCMS SHOP v 1.1 by enabling SQL injection attacks through the Ant_Message.php file.
4
What can be done to fix CVE-2021-38732?
To fix CVE-2021-38732, it is recommended to update SEMCMS SHOP to a patched version or apply a security patch provided by the vendor.
5
Where can I find more information about CVE-2021-38732?
More information about CVE-2021-38732 can be found at the following references: [link1](https://github.com/BigTiger2020/SCSHOP/blob/main/semcms-3.md), [link2](https://www.sem-cms.cn/wenda/view-56.html).