CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN08026319/ |
|
History
Thu, 23 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2026-04-23T04:15:33.414Z
Reserved: 2026-04-13T23:51:50.290Z
Link: CVE-2026-40529
No data.
Status : Received
Published: 2026-04-23T05:16:04.583
Modified: 2026-04-23T05:16:04.583
Link: CVE-2026-40529
No data.
OpenCVE Enrichment
No data.
Weaknesses