RESPONSIVE 3D SLIDER [morpheus-slider] <= 1.2 (unfixed + closed)
unknown
[en] The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so i...
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Sep 20, 2021
CVE-2021-24398 on NVD →
Responsive 3D Slider <= 1.2 - Authenticated (Admin+) SQL Injection
high
The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we...
- CVSS:
- 7.2
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 22, 2021
CVE-2021-24398 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database