ZeroHour

CVE-2021-24626

PoC ×2
CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
Description

The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL Injection

Vendors
chameleon css project
Products
chameleon css
Ecosystems
WordPress
Weakness
CWE-89, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.