CVE-2021-24827
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue
- Affected products
- Asgaros Forum
- Asgaros Asgaros Forum
- < 1.15.13
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 13.3% (96th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2021-11-08
CVE-2021-24827 at NVD
2 known exploits for CVE-2021-24827
Proof-of-concept code and exploit modules indexed by Sploitus