The SpiderCatalog WordPress plugin... CVE-2021-24625

6.5 AV AC AU C I A
发布: 2021-11-08
修订: 2024-11-21

The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before using them in a SQL statement, leading to a SQL injection when adding a category

0%
暂无可用Exp或PoC
当前有1条受影响产品信息