CVE-2021-39165 Information
Jun 07, 2022
cve
Description
Cachet is an open source status page. With Cachet prior to and including 2.3.18 there is a SQL injection which is in the SearchableTraitscopeSearch(). Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator’s password and session. The original repository of Cachet https://github.com/CachetHQ/Cachet is not active the stable version 2.3.18 and it’s developing 2.4 branch is affected.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/fiveai/Cachet/commit/27bca8280419966ba80c6fa283d985ddffa84bb6 https://github.com/fiveai/Cachet/security/advisories/GHSA-79mg-4w23-4fqc
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: