CVE-2021-24139
Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
Record summary
CVE-2021-24139 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 24, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
photo_galleryBrowse 10web / photo_gallery | VulnCheck | Version data not supplied | |
Photo Gallery by 10Web | CVE List | 1.5.55 to < 1.5.55 | affected |
Nuclei templates
1ProjectDiscoveryCRITICAL10Web Photo Gallery < 1.5.55 - SQL InjectionCVSS 9.8
WordPress plugin 10Web Photo Gallery versions before 1.5.55 contains a SQL injection caused by unvalidated input in the 'bwg_search_x' parameter in frontend/models/model.php, letting attackers execute arbitrary SQL commands, exploit requires attacker to control the 'bwg_search_x' parameter.
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise.
Remediation
Update to version 1.5.55 or later.
Source: ProjectDiscovery