CVE-2021-37413

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.
Configurations

Configuration 1 (hide)

cpe:2.3:a:grandcom:dynweb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:15

Type Values Removed Values Added
References () https://github.com/martinkubecka/CVE-References/blob/main/CVE-2021-37413.md - Exploit, Third Party Advisory () https://github.com/martinkubecka/CVE-References/blob/main/CVE-2021-37413.md - Exploit, Third Party Advisory
References () https://www.grandcom.sk - Product () https://www.grandcom.sk - Product

01 Jun 2022, 19:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CWE CWE-89
CPE cpe:2.3:a:grandcom:dynweb:*:*:*:*:*:*:*:*
References (MISC) https://github.com/martinkubecka/CVE-References/blob/main/CVE-2021-37413.md - (MISC) https://github.com/martinkubecka/CVE-References/blob/main/CVE-2021-37413.md - Exploit, Third Party Advisory
References (MISC) https://www.grandcom.sk - (MISC) https://www.grandcom.sk - Product

19 May 2022, 15:35

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-19 15:15

Updated : 2024-11-21 06:15


NVD link : CVE-2021-37413

Mitre link : CVE-2021-37413

CVE.ORG link : CVE-2021-37413


JSON object : View

Products Affected

grandcom

  • dynweb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')