CVE-2021-41765
9.8
CRITICAL
CVSS 3.1
EPSS 67.8%
描述
A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An attacker who gets an admin user session cookie can use the session cookie to execute arbitrary code on the server.
如何修補 CVE-2021-41765
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
- —未列出修補版本
CVE-2021-41765 正在被利用嗎?
可能 — EPSS 為 67.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 9.5.0, <= 9.5.0, >= 9.6.0, <= 9.6.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |