Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-4298

A vulnerability classified as critical has been found in Hesburgh Libraries of Notre Dame Sipity. This affects the function SearchCriteriaForWorksParameter of the file app/parameters/sipity/parameters/search_criteria_for_works_parameter.rb. The manipulation leads to sql injection. Upgrading to version 2021.8 is able to address this issue. The patch is named d1704c7363b899ffce65be03a796a0ee5fdbfbdc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217179.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.6%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 5.2
Products affected by CVE-2021-4298
  • Nd » Sipity » Version: 2015.1
    cpe:2.3:a:nd:sipity:2015.1
  • Nd » Sipity » Version: 2015.10
    cpe:2.3:a:nd:sipity:2015.10
  • Nd » Sipity » Version: 2015.11
    cpe:2.3:a:nd:sipity:2015.11
  • Nd » Sipity » Version: 2015.12
    cpe:2.3:a:nd:sipity:2015.12
  • Nd » Sipity » Version: 2015.13
    cpe:2.3:a:nd:sipity:2015.13
  • Nd » Sipity » Version: 2015.14
    cpe:2.3:a:nd:sipity:2015.14
  • Nd » Sipity » Version: 2015.2
    cpe:2.3:a:nd:sipity:2015.2
  • Nd » Sipity » Version: 2015.3
    cpe:2.3:a:nd:sipity:2015.3
  • Nd » Sipity » Version: 2015.4
    cpe:2.3:a:nd:sipity:2015.4
  • Nd » Sipity » Version: 2015.5
    cpe:2.3:a:nd:sipity:2015.5
  • Nd » Sipity » Version: 2015.6
    cpe:2.3:a:nd:sipity:2015.6
  • Nd » Sipity » Version: 2015.7
    cpe:2.3:a:nd:sipity:2015.7
  • Nd » Sipity » Version: 2015.8
    cpe:2.3:a:nd:sipity:2015.8
  • Nd » Sipity » Version: 2015.9
    cpe:2.3:a:nd:sipity:2015.9
  • Nd » Sipity » Version: 2016.1
    cpe:2.3:a:nd:sipity:2016.1
  • Nd » Sipity » Version: 2016.10
    cpe:2.3:a:nd:sipity:2016.10
  • Nd » Sipity » Version: 2016.11
    cpe:2.3:a:nd:sipity:2016.11
  • Nd » Sipity » Version: 2016.12
    cpe:2.3:a:nd:sipity:2016.12
  • Nd » Sipity » Version: 2016.13
    cpe:2.3:a:nd:sipity:2016.13
  • Nd » Sipity » Version: 2016.14
    cpe:2.3:a:nd:sipity:2016.14
  • Nd » Sipity » Version: 2016.15
    cpe:2.3:a:nd:sipity:2016.15
  • Nd » Sipity » Version: 2016.16
    cpe:2.3:a:nd:sipity:2016.16
  • Nd » Sipity » Version: 2016.17
    cpe:2.3:a:nd:sipity:2016.17
  • Nd » Sipity » Version: 2016.18
    cpe:2.3:a:nd:sipity:2016.18
  • Nd » Sipity » Version: 2016.19
    cpe:2.3:a:nd:sipity:2016.19
  • Nd » Sipity » Version: 2016.2
    cpe:2.3:a:nd:sipity:2016.2
  • Nd » Sipity » Version: 2016.20
    cpe:2.3:a:nd:sipity:2016.20
  • Nd » Sipity » Version: 2016.21
    cpe:2.3:a:nd:sipity:2016.21
  • Nd » Sipity » Version: 2016.22
    cpe:2.3:a:nd:sipity:2016.22
  • Nd » Sipity » Version: 2016.23
    cpe:2.3:a:nd:sipity:2016.23
  • Nd » Sipity » Version: 2016.24
    cpe:2.3:a:nd:sipity:2016.24
  • Nd » Sipity » Version: 2016.25
    cpe:2.3:a:nd:sipity:2016.25
  • Nd » Sipity » Version: 2016.26
    cpe:2.3:a:nd:sipity:2016.26
  • Nd » Sipity » Version: 2016.27
    cpe:2.3:a:nd:sipity:2016.27
  • Nd » Sipity » Version: 2016.28
    cpe:2.3:a:nd:sipity:2016.28
  • Nd » Sipity » Version: 2016.3
    cpe:2.3:a:nd:sipity:2016.3
  • Nd » Sipity » Version: 2016.4
    cpe:2.3:a:nd:sipity:2016.4
  • Nd » Sipity » Version: 2016.5
    cpe:2.3:a:nd:sipity:2016.5
  • Nd » Sipity » Version: 2016.6
    cpe:2.3:a:nd:sipity:2016.6
  • Nd » Sipity » Version: 2016.7
    cpe:2.3:a:nd:sipity:2016.7
  • Nd » Sipity » Version: 2016.8
    cpe:2.3:a:nd:sipity:2016.8
  • Nd » Sipity » Version: 2016.9
    cpe:2.3:a:nd:sipity:2016.9
  • Nd » Sipity » Version: 2017.1
    cpe:2.3:a:nd:sipity:2017.1
  • Nd » Sipity » Version: 2017.10
    cpe:2.3:a:nd:sipity:2017.10
  • Nd » Sipity » Version: 2017.11
    cpe:2.3:a:nd:sipity:2017.11
  • Nd » Sipity » Version: 2017.2
    cpe:2.3:a:nd:sipity:2017.2
  • Nd » Sipity » Version: 2017.3
    cpe:2.3:a:nd:sipity:2017.3
  • Nd » Sipity » Version: 2017.4
    cpe:2.3:a:nd:sipity:2017.4
  • Nd » Sipity » Version: 2017.5
    cpe:2.3:a:nd:sipity:2017.5
  • Nd » Sipity » Version: 2017.6
    cpe:2.3:a:nd:sipity:2017.6
  • Nd » Sipity » Version: 2017.7
    cpe:2.3:a:nd:sipity:2017.7
  • Nd » Sipity » Version: 2017.8
    cpe:2.3:a:nd:sipity:2017.8
  • Nd » Sipity » Version: 2017.9
    cpe:2.3:a:nd:sipity:2017.9
  • Nd » Sipity » Version: 2018.1
    cpe:2.3:a:nd:sipity:2018.1
  • Nd » Sipity » Version: 2018.10
    cpe:2.3:a:nd:sipity:2018.10
  • Nd » Sipity » Version: 2018.2
    cpe:2.3:a:nd:sipity:2018.2
  • Nd » Sipity » Version: 2018.3
    cpe:2.3:a:nd:sipity:2018.3
  • Nd » Sipity » Version: 2018.4
    cpe:2.3:a:nd:sipity:2018.4
  • Nd » Sipity » Version: 2018.5
    cpe:2.3:a:nd:sipity:2018.5
  • Nd » Sipity » Version: 2018.6
    cpe:2.3:a:nd:sipity:2018.6
  • Nd » Sipity » Version: 2018.7
    cpe:2.3:a:nd:sipity:2018.7
  • Nd » Sipity » Version: 2018.8
    cpe:2.3:a:nd:sipity:2018.8
  • Nd » Sipity » Version: 2018.9
    cpe:2.3:a:nd:sipity:2018.9
  • Nd » Sipity » Version: 2019.1
    cpe:2.3:a:nd:sipity:2019.1
  • Nd » Sipity » Version: 2019.10
    cpe:2.3:a:nd:sipity:2019.10
  • Nd » Sipity » Version: 2019.11
    cpe:2.3:a:nd:sipity:2019.11
  • Nd » Sipity » Version: 2019.12
    cpe:2.3:a:nd:sipity:2019.12
  • Nd » Sipity » Version: 2019.13
    cpe:2.3:a:nd:sipity:2019.13
  • Nd » Sipity » Version: 2019.14
    cpe:2.3:a:nd:sipity:2019.14
  • Nd » Sipity » Version: 2019.15
    cpe:2.3:a:nd:sipity:2019.15
  • Nd » Sipity » Version: 2019.16
    cpe:2.3:a:nd:sipity:2019.16
  • Nd » Sipity » Version: 2019.17
    cpe:2.3:a:nd:sipity:2019.17
  • Nd » Sipity » Version: 2019.2
    cpe:2.3:a:nd:sipity:2019.2
  • Nd » Sipity » Version: 2019.3
    cpe:2.3:a:nd:sipity:2019.3
  • Nd » Sipity » Version: 2019.4
    cpe:2.3:a:nd:sipity:2019.4
  • Nd » Sipity » Version: 2019.5
    cpe:2.3:a:nd:sipity:2019.5
  • Nd » Sipity » Version: 2019.6
    cpe:2.3:a:nd:sipity:2019.6
  • Nd » Sipity » Version: 2019.7
    cpe:2.3:a:nd:sipity:2019.7
  • Nd » Sipity » Version: 2019.8
    cpe:2.3:a:nd:sipity:2019.8
  • Nd » Sipity » Version: 2019.9
    cpe:2.3:a:nd:sipity:2019.9
  • Nd » Sipity » Version: 2020.1
    cpe:2.3:a:nd:sipity:2020.1
  • Nd » Sipity » Version: 2020.10
    cpe:2.3:a:nd:sipity:2020.10
  • Nd » Sipity » Version: 2020.11
    cpe:2.3:a:nd:sipity:2020.11
  • Nd » Sipity » Version: 2020.12
    cpe:2.3:a:nd:sipity:2020.12
  • Nd » Sipity » Version: 2020.13
    cpe:2.3:a:nd:sipity:2020.13
  • Nd » Sipity » Version: 2020.14
    cpe:2.3:a:nd:sipity:2020.14
  • Nd » Sipity » Version: 2020.2
    cpe:2.3:a:nd:sipity:2020.2
  • Nd » Sipity » Version: 2020.3
    cpe:2.3:a:nd:sipity:2020.3
  • Nd » Sipity » Version: 2020.4
    cpe:2.3:a:nd:sipity:2020.4
  • Nd » Sipity » Version: 2020.5
    cpe:2.3:a:nd:sipity:2020.5
  • Nd » Sipity » Version: 2020.6
    cpe:2.3:a:nd:sipity:2020.6
  • Nd » Sipity » Version: 2020.7
    cpe:2.3:a:nd:sipity:2020.7
  • Nd » Sipity » Version: 2020.8
    cpe:2.3:a:nd:sipity:2020.8
  • Nd » Sipity » Version: 2020.9
    cpe:2.3:a:nd:sipity:2020.9
  • Nd » Sipity » Version: 2021.1
    cpe:2.3:a:nd:sipity:2021.1
  • Nd » Sipity » Version: 2021.2
    cpe:2.3:a:nd:sipity:2021.2
  • Nd » Sipity » Version: 2021.3
    cpe:2.3:a:nd:sipity:2021.3
  • Nd » Sipity » Version: 2021.4
    cpe:2.3:a:nd:sipity:2021.4
  • Nd » Sipity » Version: 2021.5
    cpe:2.3:a:nd:sipity:2021.5
  • Nd » Sipity » Version: 2021.6
    cpe:2.3:a:nd:sipity:2021.6
  • Nd » Sipity » Version: 2021.7
    cpe:2.3:a:nd:sipity:2021.7


Contact Us

Shodan ® - All rights reserved