CVE-2021-41765
9.8
CRITICAL
CVSS 3.1
EPSS 67.8%
Description
A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An attacker who gets an admin user session cookie can use the session cookie to execute arbitrary code on the server.
How to fix CVE-2021-41765
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- —no fix listed
Is CVE-2021-41765 being exploited?
Likely — EPSS is 67.8%, placing CVE-2021-41765 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- >= 9.5.0, <= 9.5.0, >= 9.6.0, <= 9.6.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |