Description
The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11469 | The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped before being inserted in sql query, therefore leading to SQL injection for users having Administrator role. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:35:20.133Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-24557
No data.
Status : Modified
Published: 2021-08-23T12:15:10.013
Modified: 2024-11-21T05:53:17.890
Link: CVE-2021-24557
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD