CVE-2024-30236

CWE-89SQL Injection3 documents3 sources
Severity
9.9CRITICAL
EPSS
0.7%
top 27.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 21.3.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 3.1 | Impact: 6.0

🔴Vulnerability Details

2
GHSA
GHSA-qw72-jmvh-wj6r: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery2024-03-28
CVEList
WordPress Contest Gallery plugin <= 21.3.4 - SQL Injection vulnerability2024-03-28
CVE-2024-30236 (CRITICAL CVSS 9.9) | Improper Neutralization of Special | cvebase.io