ZeroHour

CVE-2021-24553

PoC ×2
CVSS 3.1
7.2 high
EPSS
2%p74
Published
()
Modified
Description

The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin

Vendors
timeline calendar project
Products
timeline calendar
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.