PoC Index

CVE-2021-24915

CRITICAL 9.8EPSS 12.7%

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
12.70% chance of exploitation in the next 30 days, 96th percentile
Nuclei
critical · CWE-89
Published
2021-11-29
Updated
2024-08-03

Proof-of-concept exploits (2)

Nuclei templates (1)

References

Related