---
title: "CVE-2021-24507"
canonical: "https://kb.cynergy.app/space/MD/923632089/CVE-2021-24507"
format: markdown
---
**Description**

Certain versions of [Astra](https://cve.report/software/brainstormforce/astra) from [Brainstormforce](https://cve.report/vendor/brainstormforce) contain the following vulnerability:

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitize or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

**Published On**

05/01/2022

**Updated On**

10/28/2022

**Trending**

TRUE

**CWE**

<u>[CWE-89](http://cwe.mitre.org/data/definitions/89.html)</u>

**Exploit**

[https://wpscan.com/vulnerability/a1a0dc0b-c351-4d46-ac9b-b297ce4d251c](https://wpscan.com/vulnerability/a1a0dc0b-c351-4d46-ac9b-b297ce4d251c) 

 

**Mitigation:**

![image](media://452115b8-2af7-4d2f-aaf4-d2cb858c4217)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Angular JS has reached End of Life, it is suggested to move to alternative frameworks

- 

|  |  |  |
| --- | --- | --- |
| Astra Pro Addon Changelog | [http://wpastra.com](http://wpastra.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Attention Required! | Cloudflare | [http://wpscan.com](http://wpscan.com)   
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |