CVE-2021-24786: Download Monitor < 4.4.5 - Admin+ SQL Injection
Published Jan 3, 2022
·Updated
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
Affected Software
1 affected component
WPChill Download Monitor Wordpress<4.4.5
Event History
Jan 3, 2022
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24786.
2
What is the severity level of CVE-2021-24786?
The severity level of CVE-2021-24786 is high with a score of 7.2.
3
Which software version is affected by CVE-2021-24786?
The Download Monitor WordPress plugin version up to and excluding 4.4.5 is affected by CVE-2021-24786.
4
What is the impact of CVE-2021-24786?
CVE-2021-24786 allows for SQL Injection, which can lead to unauthorized access or data manipulation.
5
How can I fix CVE-2021-24786?
To fix CVE-2021-24786, update the Download Monitor WordPress plugin to version 4.4.5 or later.