CVE-2021-24295: Time-based Blind SQL Injection in Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The updatelog function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ctsfwpasskey cookie and then manually setting a separate ctsfwpassed cookie and disallowing it from being reset.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24295?
CVE-2021-24295 refers to an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, Firewall by CleanTalk WordPress Plugin before version 5.153.4.
How severe is CVE-2021-24295?
CVE-2021-24295 has a severity score of 7.5, which is considered high.
Which software versions are affected by CVE-2021-24295?
CVE-2021-24295 affects CleanTalk Spam Protection, Antispam, Firewall WordPress Plugin versions before 5.153.4.
How can I fix CVE-2021-24295?
To fix CVE-2021-24295, update CleanTalk Spam Protection, Antispam, Firewall WordPress Plugin to version 5.153.4 or later.
Where can I find more information about CVE-2021-24295?
You can find more information about CVE-2021-24295 at the following references: [1] [2]