webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:22:25.688Z

Reserved: 2021-10-04T00:00:00

Link: CVE-2021-41920

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-08T16:15:08.393

Modified: 2024-11-21T06:26:57.373

Link: CVE-2021-41920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.