CRITICAL

CVE-2021-24741

CVSS v3

9.8

CRITICAL

EPSS Score

58.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

Technical details

Published
9/20/2021

Frequently asked questions

What is CVE-2021-24741?

The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.

Is CVE-2021-24741 actively exploited?

Active exploitation of CVE-2021-24741 has not been confirmed. The EPSS score is 58.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-24741?

CVE-2021-24741 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-24741 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.