Time-Based SQL Injection Vulnerability in The Video Gallery Plugin
CVE-2024-10247

7.2HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
6 December 2024

Summary

The Video Gallery – Best WordPress YouTube Gallery Plugin, used extensively for showcasing YouTube content on WordPress sites, is susceptible to a time-based SQL injection vulnerability. This issue arises from insufficient escaping of user-supplied parameters and flawed preparation of SQL queries. Authenticated attackers with Administrator-level access can exploit this vulnerability to inject additional SQL queries into existing queries. This manipulation could potentially enable these attackers to extract sensitive information stored within the database, posing significant risks to the integrity of user data and application security.

Affected Version(s)

Video Gallery – YouTube Gallery and Vimeo Gallery * <= 2.4.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tmrswrr
.