CVE-2021-44567: SQL Injection
Published Feb 22, 2022
·Updated
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
Affected Software
1 affected component
RosarioSIS RosarioSIS<7.6.1
Remediation
Patch Available
Event History
Feb 22, 2022
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
Description
Apr 11, 2025
Exploit Published
12:00 AM
Known Exploited
05:48 AM
Frequently Asked Questions
1
What is the vulnerability ID for this SQL Injection vulnerability?
The vulnerability ID for this SQL Injection vulnerability is CVE-2021-44567.
2
What is the severity of CVE-2021-44567?
CVE-2021-44567 has a severity score of 9.8 (Critical).
3
How does the SQL Injection vulnerability in RosarioSIS before 7.6.1 occur?
The SQL Injection vulnerability in RosarioSIS before 7.6.1 occurs via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
4
Which software versions are affected by CVE-2021-44567?
RosarioSIS versions up to 7.6.1 are affected by CVE-2021-44567.
5
How can I fix the SQL Injection vulnerability in RosarioSIS?
To fix the SQL Injection vulnerability in RosarioSIS, update to version 7.6.1 or later.