CVE-2021-24848

The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:frenify:mediamatic:*:*:*:*:*:wordpress:*:*

History

10 Jan 2022, 16:15

Type Values Removed Values Added
Summary The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin through 2.7, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection

16 Dec 2021, 17:06

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/156d4faf-7d34-4d9f-a654-9064d4eb3aea - (MISC) https://wpscan.com/vulnerability/156d4faf-7d34-4d9f-a654-9064d4eb3aea - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CPE cpe:2.3:a:frenify:mediamatic:*:*:*:*:*:wordpress:*:*

13 Dec 2021, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-13 11:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-24848

Mitre link : CVE-2021-24848

CVE.ORG link : CVE-2021-24848


JSON object : View

Products Affected

frenify

  • mediamatic
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')