WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress 的Contest Gallery 插件 13.1.0.6之前版本存在SQL注入漏洞,该漏洞源于插件没有功能检查,在从库中导出用户时,在SQL语句中使用cg search用户名原始参数之前,没有对其进行清理或转义,攻击者可利用该漏洞执行SQL注入攻击,以及获取所有在博客上注册的用户的列表,包括他们的用户名和电子邮件地址。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Contest Gallery – Photo Contest Plugin for WordPress | 13.1.0.6 ~ 13.1.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The plugin does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24915.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24822 | Stylish Cost Calculator < 7.04 - Subscriber+ Unauthorised AJAX Calls to Stored XSS | |
| CVE-2017-20008 | myCRED < 1.7.8 - Reflected Cross-Site Scripting | |
| CVE-2021-24745 | About Author Box < 1.0.2 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24748 | Email Before Download < 6.8 - Admin+ SQL Injection | |
| CVE-2021-24749 | URL Shortify < 1.5.1 - Arbitrary Link/Group Deletion via CSRF | |
| CVE-2021-24751 | GenerateBlocks < 1.4.0 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24755 | myCred < 2.3 - Subscriber+ SQL Injection | |
| CVE-2021-24768 | WP RSS Aggregator < 4.19.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24811 | Shop Page WP < 1.2.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24927 | My Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting | |
| CVE-2021-24842 | Bulk Datetime Change < 1.12 - Missing Authorisation | |
| CVE-2021-24860 | BSK PDF Manager < 3.1.2 - Admin+ SQL Injection | |
| CVE-2021-24876 | Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24883 | Popup Anything < 2.0.4 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24889 | Ninja Forms < 3.6.4 - Admin+ SQL Injection | |
| CVE-2021-24899 | Media-Tags <= 3.2.0.2 - Admin+ Stored Cross-Site Scripting | |
| CVE-2021-24908 | Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting | |
| CVE-2021-24918 | Smash Balloon Social Post Feed < 4.0.1 - Subscriber+ Arbitrary Plugin Settings Update to S |
No comments yet