CVE-2021-24360
The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks
- Affected products
- Yes/No Chart Wordpress Plugin
- Kohsei-works Yes\/no Chart
- < 1.0.12
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.2% (65th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2021-06-14
CVE-2021-24360 at NVD
1 known exploit for CVE-2021-24360
Proof-of-concept code and exploit modules indexed by Sploitus