CVE-2021-24321: Bello < 1.6.0 - Unauthenticated Blind SQL Injection
The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the btbblistingfieldpricerangeto, btbblistingfieldnowopen, btbblistingfieldmylng, listinglistview and btbblistingfieldmylat parameters before using them in a SQL statement, leading to SQL Injection issues
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24321?
CVE-2021-24321 is classified as a High severity vulnerability due to potential SQL injection risks.
How do I fix CVE-2021-24321?
To fix CVE-2021-24321, update the Bello theme to version 1.6.0 or later.
What does CVE-2021-24321 affect?
CVE-2021-24321 affects the Bello - Directory & Listing WordPress theme versions prior to 1.6.0.
What are the potential consequences of CVE-2021-24321?
Exploitation of CVE-2021-24321 can lead to unauthorized access to the database and data manipulation.
What components are involved in CVE-2021-24321?
CVE-2021-24321 involves unsanitized parameters in SQL statements, specifically related to listing functionalities in the Bello theme.