Record summary

CVE-2021-24139 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 24, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Photo Gallery by 10Web

CVE List1.5.55 to < 1.5.55affected

Nuclei templates

1
ProjectDiscoveryCRITICAL10Web Photo Gallery < 1.5.55 - SQL InjectionCVSS 9.8

WordPress plugin 10Web Photo Gallery versions before 1.5.55 contains a SQL injection caused by unvalidated input in the 'bwg_search_x' parameter in frontend/models/model.php, letting attackers execute arbitrary SQL commands, exploit requires attacker to control the 'bwg_search_x' parameter.

Impact

Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise.

Remediation

Update to version 1.5.55 or later.

WeaknessesCWE-89
Authorsriteshs4hu
Template tagscvecve2021wpwp-pluginsqliphoto-gallery10webvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:10web:photo_gallery:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2