CVE-2021-38737: SQL Injection
Published Oct 28, 2022
·Updated
SEMCMS v 1.1 is vulnerable to SQL Injection via AntPro.php.
Affected Software
1 affected component
Sem-cms Semcms=1.1
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for SEMCMS v 1.1?
The vulnerability ID for SEMCMS v 1.1 is CVE-2021-38737.
2
What is the severity level of CVE-2021-38737?
The severity level of CVE-2021-38737 is critical with a score of 9.8.
3
How does SEMCMS v 1.1 become vulnerable to SQL Injection?
SEMCMS v 1.1 becomes vulnerable to SQL Injection through the Ant_Pro.php file.
4
How can I fix the SQL Injection vulnerability in SEMCMS v 1.1?
To fix the SQL Injection vulnerability in SEMCMS v 1.1, you should apply the patch or update provided by the vendor.
5
Where can I find more information about CVE-2021-38737?
You can find more information about CVE-2021-38737 at the following references: [reference 1](https://github.com/BigTiger2020/SCSHOP/blob/main/semcms-6.md) and [reference 2](https://www.sem-cms.cn/wenda/view-56.html).