CVE-2021-24627
G Auto-Hyperlink <= 1.0.1 - Admin+ SQL Injection
Record summary
CVE-2021-24627 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
G Auto-Hyperlink | CVE List | 1.0.1 to ≤ 1.0.1 | affected |
Nuclei templates
1ProjectDiscoveryHIGHG Auto-Hyperlink <= 1.0.1 - SQL InjectionCVSS 7.2
The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection
Impact
Authenticated administrators can exploit SQL injection in the admin dashboard to extract database contents, potentially exposing sensitive WordPress configuration and user data.
Remediation
Update to G Auto-Hyperlink version 1.0.2 or later.
Source: ProjectDiscovery