CVE-2021-47720

O

rangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attackers can inject malicious SQL code into parameters like old_project_id, project_id, uuid, and uniqid to potentially extract or modify database information.

Configurations

Configuration 1 (hide)

cpe:2.3:a:orangescrum:orangescrum:1.8.0:*:*:*:*:*:*:*

History

31 Dec 2025, 17:15

Type Values Removed Values Added
First Time Orangescrum
Orangescrum orangescrum
CPE cpe:2.3:a:orangescrum:orangescrum:1.8.0:*:*:*:*:*:*:*
References () https://www.exploit-db.com/exploits/50553 - () https://www.exploit-db.com/exploits/50553 - Exploit
References () https://www.orangescrum.org/ - () https://www.orangescrum.org/ - Product
References () https://www.vulncheck.com/advisories/orangescrum-authenticated-sql-injection-via-multiple-parameters - () https://www.vulncheck.com/advisories/orangescrum-authenticated-sql-injection-via-multiple-parameters - Third Party Advisory

23 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-23 20:15

Updated : 2025-12-31 17:15


NVD link : CVE-2021-47720

Mitre link : CVE-2021-47720

CVE.ORG link : CVE-2021-47720


JSON object : View

Products Affected
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')