CVE-2021-40842
9.8 CRITICALProofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console
Published: 2021-10-13 · Last updated: 2026-06-17
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-89
Affected products
| Vendor | Product |
|---|---|
| proofpoint | insider_threat_management_server |
Description
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthenticated APIs. A malicious URL visited by anyone with network access to the server could be used to blindly execute arbitrary SQL statements on the backend database. Version 7.12.0 and all versions prior to 7.11.2 are affected.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2021-40842
- [Vendor advisory]https://www.proofpoint.com/us/security/security-advisories
- [Vendor advisory]https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0008
- [Vendor advisory]https://www.proofpoint.com/us/security/security-advisories
- [Vendor advisory]https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0008
Related CVEs
Same vendor
- CVE-2021-40843 — Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console (7.3 HIGH)
- CVE-2021-39304 — Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass (7.5 HIGH)
Same CWE
- CVE-2026-52715 — Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions (9.3 CRITICAL)
- CVE-2026-52712 — Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions (7.6 HIGH)
- CVE-2026-49772 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events C... (9.3 CRITICAL)
- CVE-2026-39581 — Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions (8.5 HIGH)
- CVE-2026-39574 — Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions (9.3 CRITICAL)