9.8
CVSSv3

CVE-2021-24762

Published: 01/02/2022 Updated: 18/03/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Perfect Survey WordPress plugin prior to 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getperfectsurvey perfect survey

Exploits

WordPress Perfect Survey plugin version 151 suffers from a remote SQL injection vulnerability ...

Github Repositories

Repository with the solutions to the Schneider Electric Hackathon (CTF) for the Cybersecurity category.

Schneider Electric CTF Write-up Repository with the solutions to the Schneider Electric Hackathon (CTF) for the Cybersecurity category Team details Team: Hackem (1 participant) Author: Galoget Latorre 🌋 GeoHome Hacking | Background A new company, GeoHome, has detected that it could have security flaws since it has never been audited Will you be able to find all the vulnera