CVE-2021-24762
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.
- Affected products
- The Perfect Survey
- Getperfectsurvey Perfect Survey
- < 1.5.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 86.8% (100th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2022-02-01
CVE-2021-24762 at NVD
9 known exploits for CVE-2021-24762
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
Exploit_CVE-2021-24762
CVE-2021-24762
Exploit for SQL Injection in Getperfectsurvey Perfect_Survey
WordPress Perfect Survey 1.5.1 SQL Injection
WordPress Perfect Survey Plugin - 1.5.1 - SQL injection (Unauthenticated) Exploit
WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
WordPress Plugin Perfect Survey 1.5.1 SQLi (Unauthenticated)
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection