← back
CVE-2021-24827observed exploitationCWE-89

Asgaros Forum < 1.15.13 - Unauthenticated SQL Injection

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 13%
from disclosure to weapon
Published on NVDNov 8
VulnCheck+1307d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue
Affected products
Unknown · Asgaros Forum