CVE-2021-24361: GeoDirectory Location Manager < 2.1.0.10 - Multiple Unauthenticated SQL Injections
Published Jun 21, 2021
·Updated
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gdpopularlocationlist did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.
Affected Software
1 affected component
AyeCode Location Manager Wordpress<2.1.0.10
Event History
Jun 21, 2021
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-24361.
2
What is the severity rating of CVE-2021-24361?
CVE-2021-24361 has a severity rating of 9.8 (critical).
3
What is the affected software of CVE-2021-24361?
The affected software of CVE-2021-24361 is the Location Manager WordPress plugin before version 2.1.0.10.
4
What is the CWE category of this vulnerability?
The CWE category of this vulnerability is CWE-89 (SQL Injection).
5
How can I fix CVE-2021-24361?
To fix CVE-2021-24361, update the Location Manager WordPress plugin to version 2.1.0.10 or later.