CVE-2021-24931
CRITICAL EXPLOITED NUCLEIWordpress Secure Copy Content Protection and Content Locking sccp_id Unauthenticated SQLi
Title source: metasploitExploitation Summary
CVE-2021-24931 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including Ron Jost, h00die, Hacker5preme (Ron Jost), Krzysztof Zając (kazet), including a Metasploit module auxiliary/scanner/http/wp_secure_copy_content_protection_sqli.
A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated SQL injection vulnerability in the WordPress plugin 'Secure Copy Content Protection and Content Locking' before version 2.8.2. It leverages the 'sccp_id' parameter in the 'ays_sccp_results_export_file' AJAX action to inject malicious SQL queries using sqlmap.
Description
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
Exploits (2)
This exploit demonstrates an unauthenticated SQL injection vulnerability in the WordPress plugin 'Secure Copy Content Protection and Content Locking' before version 2.8.2. It leverages the 'sccp_id' parameter in the 'ays_sccp_results_export_file' AJAX action to inject malicious SQL queries using sqlmap.
This Metasploit module exploits an unauthenticated SQL injection vulnerability in the WordPress Secure Copy Content Protection plugin (CVE-2021-24931) via the `sccp_id[]` parameter to dump usernames and password hashes from the `wp_users` table.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H