Candidate: CVE-2021-3286 PublicDate: 2021-01-26 18:16:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3286 https://github.com/spotweb/spotweb/issues/653 Description: SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_spotweb: upstream_spotweb: not-affected (debian: Incomplete fix for CVE-2020-35545 not applied) precise/esm_spotweb: DNE trusty_spotweb: ignored (out of standard support) trusty/esm_spotweb: DNE xenial_spotweb: DNE bionic_spotweb: not-affected (20130826+dfsg3-4) focal_spotweb: not-affected (20130826+dfsg3-4) groovy_spotweb: not-affected (20130826+dfsg3-4) devel_spotweb: not-affected (20130826+dfsg3-4)