.. / CVE-2021-24762

Exploit for WordPress Perfect Survey <1.5.2 - SQL Injection (CVE-2021-24762)

Description:

Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

Nuclei Template

View the template here CVE-2021-24762.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24762.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-24762
https://github.com/cckuailong/reapoc/tree/main/2021/CVE-2021-24762/vultarget
https://www.exploit-db.com/exploits/50766
https://wpscan.com/vulnerability/c1620905-7c31-4e62-80f5-1d9635be11ad