CVE-2021-42655
Description
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A SQL injection vulnerability in SiteServer CMS V6.15.51 allows authenticated attackers to execute arbitrary SQL commands via the `/api/pages/cms/libraryText/list` endpoint.
Vulnerability
SiteServer CMS version 6.15.51 is affected by a SQL injection vulnerability in the /api/pages/cms/libraryText/list endpoint [1][3]. The keyword parameter in the JSON POST body is not properly sanitized, allowing an attacker to inject SQL commands. The vulnerability requires the attacker to have a valid session (i.e., must be authenticated) [3].
Exploitation
An attacker with a valid login session sends a crafted POST request to /api/pages/cms/libraryText/list with Content-Type application/json. The JSON body includes "keyword":"' and 1=(select @@Version)--" (or similar SQL payload) to trigger the injection. The exploit does not require special privileges beyond standard user access [3].
Impact
Successful exploitation allows the attacker to execute arbitrary SQL commands against the underlying SQL Server database. This can lead to disclosure of sensitive data (e.g., user credentials, application content) and potential modification or deletion of database records [1][3].
Mitigation
As of the available references, no official patched version has been released. Users should upgrade to a newer version if available, or apply input validation and parameterized queries to the affected endpoint. Monitor the vendor's GitHub repository for future fixes [1][2]. Workarounds include restricting access to the endpoint and reviewing database permissions.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
SSCMSNuGet | <= 6.15.51 | — |
Affected products
2- SiteServer/CMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-5xr5-v2h7-2w7wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-42655ghsaADVISORY
- github.com/siteserver/cms/issues/3237ghsax_refsource_MISCWEB
- github.com/siteserver/cms/releases/download/siteserver-v6.15.51/siteserver_install.zipmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.