Vulnerability Description
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asgaros | Asgaros Forum | < 1.15.13 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2611560/asgaros-forumPatchThird Party Advisory
- https://wpscan.com/vulnerability/36cc5151-1d5e-4874-bcec-3b6326235db1ExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2611560/asgaros-forumPatchThird Party Advisory
- https://wpscan.com/vulnerability/36cc5151-1d5e-4874-bcec-3b6326235db1ExploitThird Party Advisory
FAQ
What is CVE-2021-24827?
CVE-2021-24827 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection is...
How severe is CVE-2021-24827?
CVE-2021-24827 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-24827?
Check the references section above for vendor advisories and patch information. Affected products include: Asgaros Asgaros Forum.