7.5
CVSSv2

CVE-2021-24507

Published: 09/08/2021 Updated: 17/08/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Astra Pro Addon WordPress plugin prior to 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

brainstormforce astra

Github Repositories

Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection - CVE-2021-24507

CVE-2021-24507 Astra Pro Addon &lt; 352 - Unauthenticated SQL Injection - CVE-2021-24507