Critical severity9.8NVD Advisory· Published Jul 26, 2021· Updated Jun 17, 2026
CVE-2021-37477
CVE-2021-37477
Description
In NavigateCMS version 2.9.4 and below, function in structure.php is vulnerable to sql injection on parameter children_order, which results in arbitrary sql query execution in the backend database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- NavigateCMS/NavigateCMSdescription
- Range: <=2.9.4
Patches
Vulnerability mechanics
References
2- gist.github.com/victomteng1997/ed429fed7de46651c89f05e7591fd4fenvdPatchThird Party Advisory
- github.com/NavigateCMS/Navigate-CMS/issues/26nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.