S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-39165 Scanner

CVE-2021-39165 scanner - SQL Injection vulnerability in Cachet

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39165
6.5
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Cachetby fiveai
<= 2.3.18
Updated Aug 21, 2026View on NVD →
Detail

Cachet is an open-source status page system designed for companies to communicate with their users about system outages and maintenance activities. It allows the creation and management of status pages that display service downtime and system performance. Cachet is widely used for its simplicity and effectiveness in delivering real-time status updates. It's developed in PHP and utilizes Laravel, making it a popular choice for businesses looking for a customizable status page solution. However, vulnerabilities like CVE-2021-39165 pose significant risks by allowing SQL injection attacks.

The vulnerability stems from improper input validation in the application's API endpoints. Specifically, the `SearchableTrait#scopeSearch()` function fails to sanitize user input for certain parameters, enabling SQL injection. Attackers can exploit this by crafting malicious requests to the API, leading to the execution of unauthorized SQL queries against the application's database.

Exploitation of this vulnerability could lead to data leakage, including sensitive customer information and system configurations. Attackers might also gain unauthorized access to administrative functions, modify data, or even escalate privileges within the application. In worst-case scenarios, it could result in a full compromise of the affected system and underlying database.

By leveraging S4E's advanced scanning capabilities, users can detect vulnerabilities like CVE-2021-39165 early in their development cycle. Our platform provides detailed insights and remediation guidance to help secure your applications against SQL injection and other critical security threats. Joining S4E enables access to a comprehensive suite of security tools designed to enhance your organization's cyber resilience.

 

References

Solution Advice
  1. Immediately upgrade Cachet to a version higher than 2.3.18 or apply the security patches provided by the vendor.
  2. Conduct thorough input validation on all user-supplied data to prevent SQL injection attacks.
  3. Utilize prepared statements and parameterized queries to ensure that SQL queries are safely executed.
  4. Regularly audit and update dependencies to mitigate vulnerabilities in third-party libraries and frameworks.
  5. Implement a robust web application firewall (WAF) to detect and block malicious requests targeting known vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.