Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify database information.
History

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Ribccs
Ribccs build Smart Erp
Vendors & Products Ribccs
Ribccs build Smart Erp

Thu, 15 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify database information.
Title Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-15T15:52:14.242Z

Updated: 2026-01-15T16:40:07.115Z

Reserved: 2026-01-14T14:39:44.737Z

Link: CVE-2021-47777

cve-icon Vulnrichment

Updated: 2026-01-15T16:40:03.031Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-15T16:16:09.677

Modified: 2026-01-16T15:55:33.063

Link: CVE-2021-47777

cve-icon Redhat

No data.