CVE-2021-44610: SQL Injection
Published Feb 23, 2022
·Updated
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) langid, (3) tmplid, (4) modrewrite (5) etadoctype. (6) metacharset, (7) defaultgroup, and (8) page group parameters in the settings mode in admin/index.php.
Affected Software
1 affected component
bloofox bloofoxCMS>=0.5.1<=0.5.2.1
Event History
Feb 23, 2022
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the SQL Injection vulnerabilities in bloofoxCMS?
The vulnerability ID for the SQL Injection vulnerabilities in bloofoxCMS is CVE-2021-44610.
2
What is the severity of CVE-2021-44610?
The severity of CVE-2021-44610 is critical.
3
How do the SQL Injection vulnerabilities in bloofoxCMS impact the software?
The SQL Injection vulnerabilities in bloofoxCMS can allow attackers to execute arbitrary SQL commands and potentially gain unauthorized access to the database.
4
Are all versions of bloofoxCMS affected by CVE-2021-44610?
No, only versions 0.5.2.1 - 0.5.1 of bloofoxCMS are affected by CVE-2021-44610.
5
Is there a fix available for the SQL Injection vulnerabilities in bloofoxCMS?
Yes, it is recommended to update bloofoxCMS to a version that includes the fix for CVE-2021-44610.