SQL Injection Vulnerability in ResourceSpace by ResourceSpace
CVE-2021-41765

9.8CRITICAL

Key Information:

Vendor

Montala

Vendor
CVE Published:
15 November 2021

What is CVE-2021-41765?

A SQL injection flaw found in the add_keyword.php file of ResourceSpace versions 9.5 and 9.6 (prior to revision 18274) enables remote unauthenticated attackers to craft specific requests that manipulate the k parameter. This exploitation could allow attackers to execute arbitrary SQL queries, exposing sensitive information from the ResourceSpace database, including user session cookies. Gaining access to an admin user's session cookie could lead to unauthorized actions on the server, highlighting significant security risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

36% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.