Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24741

Опубликовано: 20 сент. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:schiocco:support_board_-_chat_and_help_desk:*:*:*:*:*:wordpress:*:*
Версия до 3.3.4 (исключая)

EPSS

Процентиль: 98%
0.58256
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
больше 3 лет назад

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

EPSS

Процентиль: 98%
0.58256
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89