Filebird 4.7.3 - Unauthenticated SQL Injection
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which invokes this function also does not have any required permissions/authentication and can be accessed by an anonymous user.
CVE-2021-24385 is a critical severity with CVSS 9.8 SQL Injection issue affecting the Plugin FileBird – WordPress Media Library Folders & File Manager. It affects 4.7.3 through 4.7.3 and is fixed in 4.7.4.
CVE-2021-24385 is tracked for the Plugin FileBird – WordPress Media Library Folders & File Manager as critical severity with CVSS 9.8. The affected range is 4.7.3 through 4.7.3. Update FileBird – WordPress Media Library Folders & File Manager to 4.7.4 or newer where that version is compatible with the site.
| Software Type | Plugin |
|---|---|
| Software Slug |
filebird
View on wordpress.org
|
| CVE | CVE-2021-24385 |
| Patched Versions |
4.7.4
|
| Affected Versions |
4.7.3 through 4.7.3
|
Related CVEs for FileBird – WordPress Media Library Folders & File Manager
These internal links group the same WordPress plugin by CVE, issue type, severity, and patch status so operators and search engines can connect the full vulnerability cluster.
FileBird – WordPress Media Library Folders & File Manager <= 6.4.8 - Authenticated (Author+) SQL Injection
FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Stored Cross-Site Scripting
FileBird <= 5.6.0 - Authenticated(Administrator+) Stored Cross-Site Scripting via Folder Import
FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecure Direct Object Reference
Filebird <= 5.1.4 - Missing Authorization via resAdminPermissionsCheck
FileBird – WordPress Media Library Folders & File Manager <= 6.5.1 - Missing Authorization to Authenticated (Author+) Global Folders Tampering
FileBird <= 6.4.9 - Improper Authorization to Authenticated (Author+) Settings Reset
Filebird <= 6.4.2.1 - Authenticated (Author+) Insecure Direct Object Reference
This record contains material that is subject to copyright
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. Read more
License: CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. Read more