Vulnerabilities > CVE-2021-24557 - Unspecified vulnerability in Nimble3 M-Vslider 2.1.3

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
nimble3

Summary

The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.

Vulnerable Configurations

Part Description Count
Application
Nimble3
2