VulnerabilityModified
CVE-2021-27828
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CRITICAL 9.1EPSS 20.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 20.28% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- in4velocity/in4suite erp
- Source
- cve@mitre.org
References
- https://www.exploit-db.com/exploits/49884Exploit, Third Party Advisory, VDB Entry
- https://www.in4velocity.com/in4suite-erp.htmlProduct, Vendor Advisory
- https://www.exploit-db.com/exploits/49884Exploit, Third Party Advisory, VDB Entry
- https://www.in4velocity.com/in4suite-erp.htmlProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.