{"id":"CVE-2021-28242","details":"SQL Injection in the \"evoadm.php\" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the \"cf_name\" parameter when creating a new filter under the \"Collections\" tab.","modified":"2026-07-09T00:13:32.569140Z","published":"2021-04-15T14:15:16.997Z","references":[{"type":"REPORT","url":"https://github.com/b2evolution/b2evolution/issues/109"},{"type":"FIX","url":"https://deadsh0t.medium.com/authenticated-boolean-based-blind-error-based-sql-injection-b752225f0644"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/162489/b2evolution-7-2-2-SQL-Injection.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/b2evolution/b2evolution","events":[{"introduced":"65e8823e1785b75331cfb094fd9f4ad0e6cdf119"},{"last_affected":"65e8823e1785b75331cfb094fd9f4ad0e6cdf119"}],"database_specific":{"cpe":"cpe:2.3:a:b2evolution:b2evolution:7.2.2:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.2.2"},{"last_affected":"7.2.2"}],"source":"CPE_STRING"}}],"versions":["7.2.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28242.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}