CVE-2021-40674: SQL Injection
Published Sep 20, 2021
·Updated
An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Sep 20, 2021
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2021-40674.
2
What is the severity of CVE-2021-40674?
The severity of CVE-2021-40674 is critical (9.8).
3
How does the SQL injection vulnerability occur in Wuzhi CMS v4.1.0?
The SQL injection vulnerability occurs in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.
4
Which version of Wuzhi CMS is affected by this vulnerability?
Wuzhi CMS version 4.1.0 is affected by this vulnerability.
5
Is there a fix available for CVE-2021-40674?
Yes, a fix is available for CVE-2021-40674. It is recommended to update Wuzhi CMS to a patched version.