CVE-2021-37291
Critical · CVSS 9.8KevinLAB Inc 4ST BEMS (Building Energy Management System) — SQL Injection (CWE-89)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-89
Description
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
Search profile — drives PoC discovery
Symbols input_idindex.phpPOST parameter
Keywords CVE-2021-372914ST BEMS SQL InjectionKevinLAB BEMS SQLiBuilding Energy Management System SQL Injectioninput_id POST index.phpKevinLAB Inc BEMS PoCzeroscience BEMS
Versions: 1.0.0
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z