PT-2021-17520 · Kentico · Kentico Cms

Anastasios Stasinopoulos

·

Published

2021-03-05

·

Updated

2021-03-15

·

CVE-2021-27581

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kentico CMS version 5.5 R2 build 5.5.3996
Description The issue concerns SQL injection via the tagname parameter in the Blog module. This allows for potential exploitation.
Recommendations For Kentico CMS version 5.5 R2 build 5.5.3996, consider restricting access to the Blog module until a fix is available, and avoid using the tagname parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27581

Affected Products

Kentico Cms