PT-2022-11777 · Yeswiki · Yeswiki

Published

2022-03-25

·

Updated

2022-03-29

·

CVE-2021-43091

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yeswiki versions prior to 4.1.0
Description An SQL Injection issue exists in Yeswiki via the email parameter in the registration form.
Recommendations For versions prior to 4.1.0, update to version 4.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the registration form until the update is applied. Avoid using the email parameter in the affected registration form until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43091
GHSA-XGX2-332H-9X6Q

Affected Products

Yeswiki