{ "schema_version": "1.4.0", "id": "GHSA-cv9q-2p8x-2xxf", "modified": "2022-05-24T22:28:33Z", "published": "2022-05-24T22:28:33Z", "aliases": [ "CVE-2021-24200" ], "details": "The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'length' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-24200" }, { "type": "WEB", "url": "https://n4nj0.github.io/advisories/wordpress-plugin-wpdatatables-ii" }, { "type": "WEB", "url": "https://wpdatatables.com/help/whats-new-changelog" }, { "type": "WEB", "url": "https://wpscan.com/vulnerability/21aa7e18-0162-45bf-a5c6-ceee64ffa1f9" } ], "database_specific": { "cwe_ids": [ "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-04-12T14:15:00Z" } }