Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-24507 PoC — Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection

Source
Associated Vulnerability
Title:Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection (CVE-2021-24507)
Description:The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues
Description
Astra Pro Addon < 3.5.2 - Unauthenticated SQL Injection - CVE-2021-24507
Readme
# CVE-2021-24507
Astra Pro Addon &lt; 3.5.2 - Unauthenticated SQL Injection - CVE-2021-24507
File Snapshot

[4.0K] /data/pocs/cb38cd156588044ab5e4dfd437cdd575706be636 ├── [3.0K] astro.py └── [ 93] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →