Логотип exploitDog
bind:CVE-2021-24943
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24943

Количество 2

Количество 2

nvd логотип

CVE-2021-24943

около 4 лет назад

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-756m-jgjv-8g68

около 4 лет назад

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24943

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CVSS3: 9.8
55%
Средний
около 4 лет назад
github логотип
GHSA-756m-jgjv-8g68

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

55%
Средний
около 4 лет назад

Уязвимостей на страницу