CVE-2021-3262
Critical · CVSS 9.8TripSpark VEO Transportation / NovusEDU — SQL Injection (CWE-89)
- CVSS
- 9.8
- nvd
- EPSS
- 1.18%
- 64th pct
- KEV
- No
- Class
- other
- CWE-89
Description
TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing Information" search queries.
Search profile — drives PoC discovery
Symbols Student Busing InformationPOST body parametersNovusEDUVEO Transportationsearch queries
Keywords CVE-2021-3262TripSparkVEO TransportationNovusEDUSQL injectionStudent Busing InformationXP_BB-20201123-184084TripSpark SQLi PoC
Versions: 2.2.x-XP_BB-20201123-184084
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0l0lsec/Sedric-Louissaint needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z