| |
Vulnerability CVE-2021-24847
Published: 2021-11-17
Description: |
The importFromRedirection AJAX action of the SEO Redirection Plugin ?????? 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed |
Type:
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))
CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
6.5/10 |
6.4/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
https://wpscan.com/vulnerability/679ca6ed-2343-43f3-9c3e-2c12e12407c1
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|