CVE-2021-24398
HIGH 7.2EPSS 1.5%
The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5 seconds it takes 10 seconds to return since the query is ran twice.
- CVSS v3.1
- 7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 1.52% chance of exploitation in the next 30 days, 73th percentile
- Published
- 2021-09-20
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- https://codevigilant.com/disclosure/2021/wp-plugin-morpheus-slider/
- https://wpscan.com/vulnerability/e6fb2256-0214-4891-b4b7-e4371a1599a5