Vulnerabilities > CVE-2021-24931 - Unspecified vulnerability in Ays-Pro Secure Copy Content Protection and Content Locking

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
ays-pro
critical

Summary

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

Vulnerable Configurations

Part Description Count
Application
Ays-Pro
182