CVE-2021-27828 EXPLOIT
9.1
CRITICAL · CVSS 3.1 · EPSS 20.3% (pctl 97)
Patch early
A public exploit exists.
Description
SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| EPSS | 20.28% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-06-01 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| in4velocity | in4suite erp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injection | 2021-05-19 |
References
→ the Explorer · watch your stack · NVD