CVE-2021-24848
Mediamatic < 2.8.1 - Subscriber+ SQL Injection
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 Dec 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection
Affected products
Unknown · Mediamatic – Media Library FoldersWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →