CVE-2021-41654: SQL Injection
Published Jun 16, 2022
·Updated
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Jun 16, 2022
CVE Published
via MITRE·11:22 AM
Data Sourced
via MITRE·11:22 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-41654?
The severity of CVE-2021-41654 is critical with a CVSS score of 9.8.
2
What is the affected software for CVE-2021-41654?
The affected software for CVE-2021-41654 is Wuzhicms version 4.1.0.
3
What is the vulnerability type for CVE-2021-41654?
The vulnerability type for CVE-2021-41654 is SQL injection.
4
How can attackers exploit CVE-2021-41654?
Attackers can exploit CVE-2021-41654 by executing arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php.
5
Is there a fix available for CVE-2021-41654?
Yes, a fix is available by updating Wuzhicms to a version that addresses the SQL injection vulnerabilities.