Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24666
HistorySep 27, 2021 - 3:25 p.m.

CVE-2021-24666 Podlove Podcast Publisher < 3.5.6 - Unauthenticated SQL Injection

2021-09-2715:25:36
CWE-89
WPScan
www.cve.org

9.7 High

AI Score

Confidence

High

0.289 Low

EPSS

Percentile

96.9%

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a ‘Social & Donations’ module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an ‘id’ and ‘category’ parameters as arguments. Both parameters can be used for the SQLi.

CNA Affected

[
  {
    "product": "Podlove Podcast Publisher",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "3.5.6",
        "status": "affected",
        "version": "3.5.6",
        "versionType": "custom"
      }
    ]
  }
]

9.7 High

AI Score

Confidence

High

0.289 Low

EPSS

Percentile

96.9%