CVE-2021-27999
Summary
| CVE | CVE-2021-27999 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-19 14:39:00 UTC |
| Updated | 2023-11-07 03:32:00 UTC |
| Description | A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the database. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Local Services Search Engine Management System Project | Local Services Search Engine Management System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Authenticated Blind & Error based SQL injection on Local Services Search Engine Management System -v 1.0 | by Tushar | Medium | medium.com | ||
| Authenticated Blind & Error based SQL injection on Local Services Search Engine Management System -v 1.0 | by Tushar | Medium | MISC | medium.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.