Vulnerability Description
The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frenify | Mediamatic | < 2.8.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/156d4faf-7d34-4d9f-a654-9064d4eb3aeaExploitThird Party Advisory
- https://wpscan.com/vulnerability/156d4faf-7d34-4d9f-a654-9064d4eb3aeaExploitThird Party Advisory
FAQ
What is CVE-2021-24848?
CVE-2021-24848 is a vulnerability with a CVSS score of 8.8 (HIGH). The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL s...
How severe is CVE-2021-24848?
CVE-2021-24848 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24848?
Check the references section above for vendor advisories and patch information. Affected products include: Frenify Mediamatic.