Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23978 | GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings. |
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:16:03.994Z
Reserved: 2021-07-23T00:00:00.000Z
Link: CVE-2021-37413
No data.
Status : Modified
Published: 2022-05-19T15:15:07.873
Modified: 2026-06-17T04:00:29.270
Link: CVE-2021-37413
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD