Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Starl23

#25264of 53,632
9.8Total CVSS
Vulnerabilities · 1
PT-2022-10073
9.8
2022-02-16
Duxcms · Duxcms · CVE-2021-3242
**Name of the Vulnerable Software and Affected Versions** DuxCMS version 3.1.3 **Description** A SQL injection issue was found in DuxCMS via the component "s/tools/SendTpl/index?keyword=". This allows for potential SQL injection attacks. **Recommendations** For DuxCMS version 3.1.3, consider restricting access to the "s/tools/SendTpl/index?keyword=" component until a patch is available. As a temporary workaround, avoid using the `keyword` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.