b2evolution Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2021-28242 - Vulnerability Database

b2evolution Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability - CVE-2021-28242

High
Reference: CVE-2021-28242
Title: b2evolution Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability
Overview:

SQL Injection in the quotevoadm.phpquot component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the quotcf_namequot parameter when creating a new filter under the quotCollectionsquot tab.