Record summary

CVE-2021-24791 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Header Footer Code Manager

CVE List1.1.14 to < 1.1.14affected

Nuclei templates

1
ProjectDiscoveryHIGHHeader Footer Code Manager < 1.1.14 - Admin+ SQL InjectionCVSS 7.2

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

Impact

Authenticated administrators can exploit time-based blind SQL injection in the Snippets dashboard, potentially extracting sensitive database contents including user credentials.

Remediation

Fixed in version 1.1.14

WeaknessesCWE-89
Authorsr3Y3r53
Template tagstime-based-sqlicve2021cvewpscansqliwpwordpresswp-pluginauthenticatedheader-footer-code-managerdraftpressvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:draftpress:header_footer_code_manager:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/wp-custom-pages/"

Source: ProjectDiscovery

References

2