CVE-2021-24951SQL Injection in Learnpress

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
0.5%
top 32.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Latest updateDec 14

Description

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-c9xv-q798-33wg: The LearnPress WordPress plugin before 42021-12-14
CVEList
LearnPress < 4.1.4 - Admin+ SQL Injection2021-12-13
CVE-2021-24951 — SQL Injection in Thimpress Learnpress | cvebase