ZeroHour

CVE-2021-24844

PoC
CVSS 3.1
7.2 high
EPSS
2%p73
Published
()
Modified
Description

The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

Vendors
wpaffiliatemanager
Products
affiliates manager
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.