CVE-2021-24748
Summary
| CVE | CVE-2021-24748 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-29 09:15:00 UTC |
| Updated | 2021-11-29 19:25:00 UTC |
| Description | The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mandsconsulting | Email Before Download | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Attention Required! | Cloudflare | MISC | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: bl4derunner
There are currently no legacy QID mappings associated with this CVE.