CVE-2021-24461: FAQ Builder < 1.3.6 - Authenticated Blind SQL Injections
Published Aug 2, 2021
·Updated
The getfaqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the getresults() DB calls, leading to SQL injection issues in the admin dashboard
Affected Software
1 affected component
ays-pro Faq Builder Wordpress<1.3.6
Event History
Aug 2, 2021
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24461.
2
What is the severity of CVE-2021-24461?
CVE-2021-24461 has a severity rating of 8.8 (high).
3
What is the affected software?
The affected software is the FAQ Builder AYS WordPress plugin version up to but excluding 1.3.6.
4
What is the impact of CVE-2021-24461?
CVE-2021-24461 allows for SQL injection issues in the admin dashboard.
5
How can I fix CVE-2021-24461?
To fix CVE-2021-24461, update the FAQ Builder AYS WordPress plugin to version 1.3.6 or later.