QID 150432
Date Published: 2021-12-03
QID 150432: WordPress Photo Gallery by Ays Plugin Authenticated Blind SQL Injections (CVE-2021-24462)
Gallery - Photo Galleys is a responsive image gallery wordpress plugin. Which allows you to add unlimited galleries and unlimited images in your preferred format.
The get_gallery_categories() and get_galleries() functions in the plugin did not use whitelist or validate the order by parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Affected versions:
before 4.4.4
Successful exploitation could allow an unauthenticated, remote attacker to manipulate SQL queries by injecting arbitrary SQL code or further exploit latent vulnerabilities in the underlying database.
Solution
Customers are advised to upgrade to Gallery - Photo Galleys 4.4.4 or later versions to remediate this vulnerability.
Vendor References
- Photo Gallery -
wpscan.com/vulnerability/e24dac6d-de48-42c1-bdde-4a45fb331376
CVEs related to QID 150432
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Photo Gallery |
|