CVE-2024-30238

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGH
EPSS
0.8%
top 26.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 21.3.2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
WordPress Photos and Files Contest Gallery plugin <= 21.3.2 - SQL Injection vulnerability2024-03-27
GHSA
GHSA-vhpq-5rff-2gh4: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery2024-03-27
CVE-2024-30238 (HIGH CVSS 8.8) | Improper Neutralization of Special | cvebase.io