Record summary

CVE-2021-24627 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

G Auto-Hyperlink

CVE List1.0.1 to ≤ 1.0.1affected

Nuclei templates

1
ProjectDiscoveryHIGHG Auto-Hyperlink <= 1.0.1 - SQL InjectionCVSS 7.2

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

Impact

Authenticated administrators can exploit SQL injection in the admin dashboard to extract database contents, potentially exposing sensitive WordPress configuration and user data.

Remediation

Update to G Auto-Hyperlink version 1.0.2 or later.

WeaknessesCWE-89
Authorstheamanrawat
Template tagscve2021cvesqliwpscanwordpresswp-pluginwpg-auto-hyperlinkauthenticatedg_auto-hyperlink_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:g_auto-hyperlink_project:g_auto-hyperlink:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/g-auto-hyperlink/
FOFA: body=/wp-content/plugins/g-auto-hyperlink/

Source: ProjectDiscovery

References

3