Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24149
HistoryMar 18, 2021 - 2:57 p.m.

CVE-2021-24149 Modern Events Calendar Lite < 5.16.6 - Authenticated SQL Injection

2021-03-1814:57:50
CWE-89
WPScan
www.cve.org
1

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.6%

Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.

CNA Affected

[
  {
    "product": "Modern Events Calendar Lite",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "5.16.6",
        "status": "affected",
        "version": "5.16.6",
        "versionType": "custom"
      }
    ]
  }
]

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.6%

Related for CVELIST:CVE-2021-24149