ZeroHour

CVE-2021-24138

PoC
CVSS 3.1
5.5 medium
EPSS
1%p67
Published
()
Modified
Description

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

Vendors
ajdg
Products
adrotate
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.