PT-2021-16373 · WordPress · Secure Copy Content Protection/Content Locking
Krzysztof Zając
·
Published
2021-12-06
·
Updated
2022-02-28
·
CVE-2021-24931
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Secure Copy Content Protection and Content Locking WordPress plugin versions prior to 2.8.2
Description:
The issue arises from the failure to escape the
sccp id parameter of the "ays sccp results export file" AJAX action, leading to an SQL injection. This AJAX action is available to both unauthenticated and authenticated users.Recommendations:
For versions prior to 2.8.2, update to version 2.8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "ays sccp results export file" AJAX action to minimize the risk of exploitation. Avoid using the
sccp id parameter in the affected AJAX action until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secure Copy Content Protection/Content Locking