Fiche vulnérabilité
CVE-2021-24848 : faille élevée frenify mediamatic (CVSS 8.8)
Description
The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 13 déc. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- frenify mediamatic