Vulnerabilities > CVE-2021-24397 - Unspecified vulnerability in Activemedia Microcopy 1.1.0

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
activemedia

Summary

The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.

Vulnerable Configurations

Part Description Count
Application
Activemedia
2