CVE-2021-24741

CRITICAL

Support Board WordPress <3.3.4 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-24741. PoCs published by dldygnl.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-24741, demonstrating multiple SQL injection vulnerabilities in Support Board v3.3.3. The PoC includes detailed HTTP requests for error-based and time-based SQLi attacks, along with a Python script for exploitation.

Description

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

Exploits (1)

nomisec WORKING POC 2 stars
by dldygnl · poc
https://github.com/dldygnl/CVE-2021-24741

This repository contains a functional exploit for CVE-2021-24741, demonstrating multiple SQL injection vulnerabilities in Support Board v3.3.3. The PoC includes detailed HTTP requests for error-based and time-based SQLi attacks, along with a Python script for exploitation.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Support Board v3.3.3
No auth needed
Prerequisites: Access to the target's ajax.php endpoint · Support Board plugin installed and active
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/ccf293ec-7607-412b-b662-5e237b8690ca
Release Notes, Vendor Advisory x_refsource_misc
https://board.support/changes

Scores

CVSS v3 9.8
EPSS 0.0552
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
schiocco/support_board_-_chat_and_help_desk < 3.3.4
Published Sep 20, 2021
Tracked Since Feb 18, 2026