Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24931
HistoryDec 06, 2021 - 3:55 p.m.

CVE-2021-24931 Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection

2021-12-0615:55:34
CWE-89
WPScan
www.cve.org
13
cve-2021-24931
wordpress
sql injection
unauthenticated
content protection

AI Score

10

Confidence

High

EPSS

0.565

Percentile

97.8%

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

CNA Affected

[
  {
    "product": "Secure Copy Content Protection and Content Locking",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "2.8.2",
        "status": "affected",
        "version": "2.8.2",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

10

Confidence

High

EPSS

0.565

Percentile

97.8%