EXPOSURES › CVE-2021-37291
CVE-2021-37291
CRITICAL
DETAIL
SourceNVD · cve
Published2022-04-11
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-37291 ↗
SHAME 35/100
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.