KANATA Limited CMS ALAYA SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in CMS ALAYA versions 7.4.1.4 and earlier, provided by KANATA Limited. This vulnerability allows an attacker with access to the administrative interface to obtain or alter information stored in the database.
Impact
Exploitation of this vulnerability could lead to unauthorized access to, or modification of, database information by an attacker with administrative privileges.
Remediation
Users are advised to update CMS ALAYA to the latest version as recommended by the developer.
Added: Apr 23, 2026, 5:19 AM
Updated: Apr 23, 2026, 5:19 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
3.1exploitability
4.8remediation
0.0relevance
6.5threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
