CVE-2021-24862
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue
- Affected products
- Registrationmagic
- Metagauss Registrationmagic
- < 5.0.1.6
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 73.3% (99th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2022-01-10
CVE-2021-24862 at NVD
6 known exploits for CVE-2021-24862
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
Wordpress RegistrationMagic Task_ids Authenticated SQL Injection
WordPress RegistrationMagic V 5.0.1.5 Plugin- SQL Injection Exploit
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
WordPress RegistrationMagic V 5.0.1.5 SQL Injection
Wordpress RegistrationMagic task_ids Authenticated SQLi