Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information including user credentials and authentication hashes.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apptha
Apptha apptha Slider Gallery Wordpress Wordpress wordpress |
|
| Vendors & Products |
Apptha
Apptha apptha Slider Gallery Wordpress Wordpress wordpress |
Tue, 09 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive database information including user credentials and authentication hashes. | |
| Title | WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-09T11:48:37.737Z
Updated: 2026-06-09T13:04:09.801Z
Reserved: 2026-06-08T11:52:26.190Z
Link: CVE-2017-20249
Updated: 2026-06-09T13:04:06.337Z
Status : Deferred
Published: 2026-06-09T13:16:34.850
Modified: 2026-06-09T13:51:18.770
Link: CVE-2017-20249
No data.