CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN08026319/ |
|
History
Tue, 28 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in CMS ALAYA Enabling Data Alteration |
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kanata
Kanata cms Alaya |
|
| Vendors & Products |
Kanata
Kanata cms Alaya |
Thu, 23 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2026-04-23T04:15:33.414Z
Updated: 2026-04-23T12:25:36.471Z
Reserved: 2026-04-13T23:51:50.290Z
Link: CVE-2026-40529
Updated: 2026-04-23T12:25:32.862Z
Status : Deferred
Published: 2026-04-23T05:16:04.583
Modified: 2026-04-23T16:23:59.233
Link: CVE-2026-40529
No data.
ReportizFlow