Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 19 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:openbmcs:openbmcs:2.4:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openbmcs
Openbmcs openbmcs |
|
| Vendors & Products |
Openbmcs
Openbmcs openbmcs |
Tue, 09 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information. | |
| Title | OpenBMCS SQL Injection via obix_test.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:05:32.506Z
Reserved: 2025-12-05T19:10:29.045Z
Link: CVE-2021-47704
Updated: 2025-12-09T21:33:58.695Z
Status : Analyzed
Published: 2025-12-09T21:15:49.200
Modified: 2025-12-19T19:34:48.567
Link: CVE-2021-47704
No data.
OpenCVE Enrichment
Updated: 2025-12-10T21:33:25Z