PT-2022-12173 · Unknown · Kreado Kreasfero

Vlynx

·

Published

2022-03-29

·

Updated

2022-04-04

·

CVE-2021-44581

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kreado Kreasfero version 1.5
Description An SQL Injection issue exists via the id parameter.
Recommendations For version 1.5, avoid using the id parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44581

Affected Products

Kreado Kreasfero