SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-24T08:41:02

Updated: 2024-08-03T16:53:17.040Z

Reserved: 2021-01-24T00:00:00

Link: CVE-2021-3286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-01-26T18:16:29.567

Modified: 2021-01-30T01:35:47.383

Link: CVE-2021-3286

cve-icon Redhat

No data.