mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-26 01:07:59 +02:00
811 B
811 B
CVE-2021-24778
Description
The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
POC
Reference
- https://wpscan.com/vulnerability/e37f9aa6-e409-4155-b8e4-566c5bce58d6
- https://wpscan.com/vulnerability/e37f9aa6-e409-4155-b8e4-566c5bce58d6
Github
No PoCs found on GitHub currently.