ZeroHour

CVE-2021-26837

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p56
Published
()
Modified
Description

SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.

Vendors
fortra
Products
delivernow
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.