Skip to content
COOEY

EXPOSURES › CVE-2021-37291

CVE-2021-37291

CRITICAL
DETAIL
SourceNVD · cve Published2022-04-11 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-37291 ↗
SHAME 35/100

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.