First published: Mon Aug 02 2021(Updated: )
The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files of the Portfolio Responsive Gallery WordPress plugin before 1.1.8 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Portfolio Responsive Gallery | <1.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2021-24457 is about two functions in the Portfolio Responsive Gallery WordPress plugin that did not use whitelist or validate the orderb parameter, allowing for SQL injection attacks.
The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php and class-portfolio-responsive-gallery-attributes-list-table.php files are affected by vulnerability CVE-2021-24457.
The severity of vulnerability CVE-2021-24457 is high, with a CVSS score of 8.8.
To fix vulnerability CVE-2021-24457, update the Portfolio Responsive Gallery WordPress plugin to version 1.1.8 or above.
The CWE ID for vulnerability CVE-2021-24457 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).