mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 02:02:23 +02:00
19 lines
1.1 KiB
Markdown
19 lines
1.1 KiB
Markdown
### [CVE-2021-24385](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24385)
|
|

|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which invokes this function also does not have any required permissions/authentication and can be accessed by an anonymous user.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/754ac750-0262-4f65-b23e-d5523995fbfa
|
|
|
|
#### Github
|
|
- https://github.com/20142995/nuclei-templates
|
|
|