CVE-2021-47720
EUVD-2025-20481723.12.2025, 20:15
Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attackers can inject malicious SQL code into parameters like old_project_id, project_id, uuid, and uniqid to potentially extract or modify database information.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| orangescrum | orangescrum | 1.8.0 |
𝑥
= Vulnerable software versions