CVE-2021-37787

The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request to the TinyMCE module
References
Link Resource
https://www.abocms.ru/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:abocms:abo.cms:*:*:*:*:*:*:*:*

History

21 May 2025, 19:28

Type Values Removed Values Added
References () https://www.abocms.ru/ - () https://www.abocms.ru/ - Product
CPE cpe:2.3:a:abocms:abo.cms:*:*:*:*:*:*:*:*
First Time Abocms abo.cms
Abocms

21 Mar 2025, 21:15

Type Values Removed Values Added
Summary
  • (es) La interfaz administrativa sin privilegios en ABO.CMS versión 5.8 a v.5.9.3 se ve afectada por una vulnerabilidad de inyección SQL a través de una solicitud HTTP POST al módulo TinyMCE.
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

11 Mar 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 18:15

Updated : 2025-05-21 19:28


NVD link : CVE-2021-37787

Mitre link : CVE-2021-37787

CVE.ORG link : CVE-2021-37787


JSON object : View

Products Affected

abocms

  • abo.cms
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')