Check & Log Email < 1.0.3 - Admin+ SQL Injections
CVE-2021-24774

7.2HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
25 October 2021

Summary

The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues

Affected Version(s)

Check & Log Email 1.0.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bl4derunner
.