CVE-2021-24462: Photo Gallery by Ays - Responsive Image Gallery < 4.4.4 - Authenticated Blind SQL Injections
The getgallerycategories() and getgalleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the getresults() DB calls, leading to SQL injection issues in the admin dashboard
Other sources
The getgallerycategories() and getgalleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the getresults() DB calls, leading to SQL injection issues in the admin dashboard
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24462.
What is the affected software?
The affected software is the Photo Gallery by Ays - Responsive Image Gallery WordPress plugin version up to exclusive 4.4.4.
How severe is CVE-2021-24462?
CVE-2021-24462 has a severity rating of 8.8 (High).
What is the CWE ID for this vulnerability?
The CWE ID for CVE-2021-24462 is CWE-89 (SQL Injection).
How can I fix CVE-2021-24462?
To fix CVE-2021-24462, update the Photo Gallery by Ays - Responsive Image Gallery WordPress plugin to version 4.4.4 or higher.