CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN08026319/ |
|
History
Thu, 23 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-04-23T04:15:33.414Z
Reserved: 2026-04-13T23:51:50.290Z
Link: CVE-2026-40529
No data.
Status : Received
Published: 2026-04-23T05:16:04.583
Modified: 2026-04-23T05:16:04.583
Link: CVE-2026-40529
No data.
OpenCVE Enrichment
No data.