CVE-2021-24463: Image Slider by Ays - Responsive Slider and Carousel < 2.5.0 - Authenticated Blind SQL Injection
The getsliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the getresults() DB calls, leading to SQL injection issues in the admin dashboard
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24463.
What is the severity rating of CVE-2021-24463?
CVE-2021-24463 has a severity rating of 8.8.
What is the affected software of CVE-2021-24463?
The affected software for CVE-2021-24463 is the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before version 2.5.0.
What is the description of CVE-2021-24463?
CVE-2021-24463 is a SQL injection vulnerability in the get_sliders() function of the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before version 2.5.0.
How can I fix CVE-2021-24463?
To fix CVE-2021-24463, it is recommended to update the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin to version 2.5.0 or newer.