Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24555
HistoryAug 23, 2021 - 11:10 a.m.

CVE-2021-24555 Diary & Availability Calendar <= 1.0.3 - Authenticated (subscriber+) SQL Injection

2021-08-2311:10:09
CWE-352
CWE-89
WPScan
www.cve.org
1

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.6%

The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check, making it available to any authenticated user.

CNA Affected

[
  {
    "product": "Diary & Availability Calendar",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThanOrEqual": "1.0.3",
        "status": "affected",
        "version": "1.0.3",
        "versionType": "custom"
      }
    ]
  }
]

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.6%

Related for CVELIST:CVE-2021-24555