CVE-2021-43091 describes an SQL Injection vulnerability in Yeswiki doryphore version 20211012, specifically within the email parameter of its registration form. This vulnerability carries a high severity CVSS score of 7.5, indicating it can be exploited remotely without user interaction to achieve high confidentiality impact. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations using the affected Yeswiki version should prioritize patching to mitigate potential data breaches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:yeswiki:yeswiki:4.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.