Description
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15425 | The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:18:42.904Z
Reserved: 2022-01-14T00:00:00.000Z
Link: CVE-2022-0228
No data.
Status : Modified
Published: 2022-02-21T11:15:09.420
Modified: 2024-11-21T06:38:11.223
Link: CVE-2022-0228
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD