mirror of
https://github.com/0xMarcio/cve.git
synced 2026-02-12 22:53:11 +00:00
18 lines
763 B
Markdown
18 lines
763 B
Markdown
### [CVE-2021-24748](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24748)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/a8625b84-337d-4c4d-a698-73e59d1f8ee1
|
|
|
|
#### Github
|
|
- https://github.com/20142995/nuclei-templates
|
|
|