关键漏洞信息 漏洞标题 Hotscot Contact Form < 1.3 - Admin+ SQL Injection 描述 The view submission functionality in the plugin makes a get request with the sub_id parameter which not sanitised, escaped or validated before inserting to a SQL statement, leading to an SQL injection. 影响插件 hotscot-contact-form (Fixed in 1.3) 漏洞等级与分类 CVE: CVE-2021-24777 Type: SQLI OWASP top 10: A1: Injection CWE: CWE-89 CVSS: 6.8 (medium) 历史与研究者 Original Researcher: Syed Sheeraz Ali of Codevigilant Verified: Yes Timeline: - Publicly Published: 2021-05-13 - Added: 2022-02-14 - Last Updated: 2022-04-08 证明概念示例 关联的其他漏洞记录 Smart Notification <= 10.3 - Unauthenticated SQL Injection XStore < 9.3.9 - Unauthenticated SQL Wow Forms <= 3.1.3 - Admin+ SQL Injection WP Coder < 2.5.4 - Admin+ SQLi WPSmartContracts < 1.3.12 - Author+ SQLi