7.5
CVSSv2

CVE-2021-30175

Published: 13/04/2021 Updated: 14/04/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

Github Repositories

Public CVE CVE Number Product CVE-2021-30175 ZEROF Web Server 10 (April 2021 version) CVE-2021-30176 ZEROF Expert pro/20 (mobile app) CVE-2021-31794 Directum 582 XSS via User-agent CVE-2022-25323 ZEROF Web Server (February 2022 version)