Time-Based SQL Injection Vulnerability in The Video Gallery Plugin
CVE-2024-10247
7.2HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 6 December 2024
Summary
The Video Gallery – Best WordPress YouTube Gallery Plugin, used extensively for showcasing YouTube content on WordPress sites, is susceptible to a time-based SQL injection vulnerability. This issue arises from insufficient escaping of user-supplied parameters and flawed preparation of SQL queries. Authenticated attackers with Administrator-level access can exploit this vulnerability to inject additional SQL queries into existing queries. This manipulation could potentially enable these attackers to extract sensitive information stored within the database, posing significant risks to the integrity of user data and application security.
Affected Version(s)
Video Gallery – YouTube Gallery and Vimeo Gallery * <= 2.4.2
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
tmrswrr