7.5
CVSSv2

CVE-2021-30176

Published: 13/04/2021 Updated: 14/04/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

Github Repositories

Public CVE CVE Number Product CVE-2021-30175 ZEROF Web Server 10 (April 2021 version) CVE-2021-30176 ZEROF Expert pro/20 (mobile app) CVE-2021-31794 Directum 582 XSS via User-agent CVE-2022-25323 ZEROF Web Server (February 2022 version)