vendor:
Secure Copy Content Protection and Content Locking
by:
Ron Jost (Hacker5preme)
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Secure Copy Content Protection and Content Locking
Affected Version From: < 2.8.2
Affected Version To: 2.8.2001
Patch Exists: YES
Related CWE: CVE-2021-24931
CPE: a:ays_pro:secure_copy_content_protection_and_content_locking
Tags: wp-plugin,cve,wp,packetstorm,unauth,wpscan,cve2021,sqli,wordpress,secure-copy-content-protection
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei References:
https://wpscan.com/vulnerability/1cd52d61-af75-43ed-9b99-b46c471c4231, https://wordpress.org/plugins/secure-copy-content-protection/, https://nvd.nist.gov/vuln/detail/CVE-2021-24931, http://packetstormsecurity.com/files/165946/WordPress-Secure-Copy-Content-Protection-And-Content-Locking-2.8.1-SQL-Injection.html
Nuclei Metadata: {'max-request': 1, 'verified': True, 'framework': 'wordpress', 'vendor': 'ays-pro', 'product': 'secure_copy_content_protection_and_content_locking'}
Platforms Tested: Ubuntu 20.04
2022
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 – SQL-Injection (Unauthenticated)
The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.
Mitigation:
Upgrade to version 2.8.2 or later.