{"cve":"CVE-2021-24915","epss":{"score":0.12004},"mitre":{"cpes":[],"created":"2021-11-29T08:25:50+00:00","description":"The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2021/24xxx/CVE-2021-24915.json","references":["https://gist.github.com/tpmiller87/6c05596fe27dd6f69f1aaba4cbb9c917","https://wpscan.com/vulnerability/45ee86a7-1497-4c81-98b8-9a8e5b3d4fac"],"title":"Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure","updated":"2024-08-03T19:49:13.959000+00:00","vendors":[],"weaknesses":["CWE-89"]},"nvd":{"cpes":["cpe:2.3:a:contest_gallery:contest_gallery:*:*:*:*:*:wordpress:*:*"],"created":"2021-11-29T09:15:07.970000+00:00","description":"The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2021/CVE-2021-24915.json","references":["https://gist.github.com/tpmiller87/6c05596fe27dd6f69f1aaba4cbb9c917","https://wpscan.com/vulnerability/45ee86a7-1497-4c81-98b8-9a8e5b3d4fac"],"title":null,"updated":"2026-06-17T03:41:07.680000+00:00","vendors":["contest_gallery","contest_gallery$PRODUCT$contest_gallery"],"weaknesses":["CWE-89"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:a:contest_gallery:contest_gallery:*:*:*:*:*:wordpress:*:*"],"providers":["nvd"]},"created":{"data":"2021-11-29T08:25:50+00:00","provider":"mitre"},"description":{"data":"The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.12004},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://gist.github.com/tpmiller87/6c05596fe27dd6f69f1aaba4cbb9c917","https://wpscan.com/vulnerability/45ee86a7-1497-4c81-98b8-9a8e5b3d4fac"],"providers":["mitre","nvd"]},"title":{"data":"Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure","provider":"mitre"},"updated":{"data":"2024-11-21T05:54:00.287000+00:00","provider":"nvd"},"vendors":{"data":["contest_gallery","contest_gallery$PRODUCT$contest_gallery"],"providers":["nvd"]},"weaknesses":{"data":["CWE-89"],"providers":["mitre","nvd"]}}}