René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

106 lines
3.3 KiB
JSON

{
"id": "CVE-2021-24847",
"sourceIdentifier": "contact@wpscan.com",
"published": "2021-11-17T11:15:08.277",
"lastModified": "2021-11-18T21:07:27.143",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The importFromRedirection AJAX action of the SEO Redirection Plugin \u00e2\u20ac\u201c 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed"
},
{
"lang": "es",
"value": "La acci\u00f3n importFromRedirection AJAX del plugin SEO Redirection Plugin - 301 Redirect Manager de WordPress versiones anteriores a 8.2, disponible para cualquier usuario autenticado, no sanea apropiadamente el par\u00e1metro offset antes de usarlo en una sentencia SQL, conllevando a una inyecci\u00f3n SQL cuando el plugin de redirecci\u00f3n tambi\u00e9n est\u00e1 instalado"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.5
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "contact@wpscan.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:wp-buy:seo_redirection-301_redirect_manager:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "8.2",
"matchCriteriaId": "DB9CD3BE-45AE-416B-BC88-C475D37EA6BC"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/679ca6ed-2343-43f3-9c3e-2c12e12407c1",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}