CVE-2021-24361 Information
Jun 07, 2022
cve
Description
In the Location Manager WordPress plugin before 2.1.0.10 the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters which are then used in a SQL statement leading to unauthenticated SQL Injection issues.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://wpgeodirectory.com/downloads/location-manager/ https://wpscan.com/vulnerability/5aff50fc-ac96-4076-a07c-bb145ae37025
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: