← Vulnerability feed

Vulnerability record · CVE-2021-41920 · published 8 October 2021

CVE-2021-41920: Webtareas project webtareas sql injection vulnerability

WWebtareas Project · Webtareas

webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.

7.5 CVSS 3.1 High EPSS 1.7% · top 23.3% CWE-89 · SQL injection
7.5CVSS 3.1 base score, v2 5.0
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41920 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44290Webtareas project webtareas sql injection vulnerabilitywebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.EPSS 3.7%9.8CVE-2022-44291Webtareas project webtareas sql injection vulnerabilitywebTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.EPSS 3.7%9.8CVE-2021-43481Webtareas project webtareas sql injection vulnerabilityAn SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.EPSS 5.6%9.3CVE-2023-53972Webtareas project webtareas sql injection vulnerabilityWebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate databas…EPSS 0.43%8.8CVE-2021-41916Webtareas project webtareas cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profil…EPSS 0.82%8.8CVE-2021-41919Webtareas project webtareas unrestricted file upload vulnerabilitywebTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is workin…EPSS 2.4%8.7CVE-2023-53971Webtareas project webtareas unrestricted file upload vulnerabilityWebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functi…EPSS 0.48%7.5CVE-2020-25733Webtareas project webtareas unrestricted file upload vulnerabilitywebTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2021-41920), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.