CVE-2021-26739
CRITICALCVSS 9.8/10EPSS 1.63%
Last modified
CVE-2021-26739 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.. EPSS estimates a 1.63% chance of exploitation in the next 30 days.
Description
SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Doyocms Project | Doyocms | 2.3 |
References
- https://github.com/millken/doyocms/issues/5Exploit, Third Party Advisory
- https://github.com/millken/doyocms/issues/5Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26739?
SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.
How severe is CVE-2021-26739?
CVE-2021-26739 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.63% probability of exploitation in the next 30 days.
How do I fix CVE-2021-26739?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-26733A broken access control vulnerability in the FirstReset_hand…7.5
- CVE-2021-26734Zscaler Client Connector Installer on Windows before version…5.5
- CVE-2021-26735The Zscaler Client Connector Installer and Unsintallers for …7.8
- CVE-2021-26736Multiple vulnerabilities in the Zscaler Client Connector Ins…7.8
- CVE-2021-26737The Zscaler Client Connector for macOS prior to 3.6 did not …4.7
- CVE-2021-26738Zscaler Client Connector for macOS prior to 3.7 had an unquo…7.8
- CVE-2021-26740Arbitrary file upload vulnerability sysupload.php in millken…9.8
- CVE-2021-26746Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.p…6.1
- CVE-2021-26747Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Sh…9.8
- CVE-2021-26750DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.…7.8
- CVE-2021-26751NeDi 1.9C allows an authenticated user to perform a SQL Inje…8.8
- CVE-2021-26752NeDi 1.9C allows an authenticated user to execute operating …8.8
Are you affected by CVE-2021-26739?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
